cpcommerce kayıtları
cpcommerce üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2008-1908Kavram kanıtı | Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .cpcommerce · cpcommerce · CWE-22 | Yüksek7,5 | — | %2,8 | 22 Nis 2008 |
30İzleyin | CVE-2007-2890Kavram kanıtı | SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via thcpcommerce · cpcommerce | Yüksek7,5 | — | %1,2 | 29 May 2007 |
30İzleyin | CVE-2007-2959Kavram kanıtı | SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via thecpcommerce · cpcommerce | Yüksek7,5 | — | %1,2 | 31 May 2007 |
30İzleyin | CVE-2008-1907Kavram kanıtı | Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQcpcommerce · cpcommerce · CWE-89 | Yüksek7,5 | — | %1,0 | 22 Nis 2008 |
30İzleyin | CVE-2009-1345Kavram kanıtı | SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_documencpcommerce · cpcommerce · CWE-89 | Yüksek7,5 | — | %1,0 | 20 Nis 2009 |
28İzleyin | CVE-2003-1500İstismar yok | PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the preficpcommerce · cpcommerce · CWE-94 | Orta6,8 | — | %3,0 | 31 Ara 2003 |
18İzleyin | CVE-2008-1906Kavram kanıtı | Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML cpcommerce · cpcommerce · CWE-79 | Orta4,3 | — | %1,7 | 22 Nis 2008 |
17İzleyin | CVE-2008-4121İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTMLcpcommerce · cpcommerce · CWE-79 | Orta4,3 | — | %1,3 | 21 Eki 2008 |
17İzleyin | CVE-2007-2968İstismar yok | Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web scrcpcommerce · cpcommerce | Orta4,3 | — | %1,2 | 31 May 2007 |
17İzleyin | CVE-2008-4637İstismar yok | Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknocpcommerce · cpcommerce · CWE-79 | Orta4,3 | — | %0,8 | 21 Eki 2008 |
- CVE-2008-190831İzleyin
Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .
YüksekCVSS 7,5Kavram kanıtıEPSS %3cpcommerce · cpcommerce22 Nis 2008
- CVE-2007-289030İzleyin
SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via th
YüksekCVSS 7,5Kavram kanıtıEPSS %1cpcommerce · cpcommerce29 May 2007
- CVE-2007-295930İzleyin
SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5Kavram kanıtıEPSS %1cpcommerce · cpcommerce31 May 2007
- CVE-2008-190730İzleyin
Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQ
YüksekCVSS 7,5Kavram kanıtıEPSS %1cpcommerce · cpcommerce22 Nis 2008
- CVE-2009-134530İzleyin
SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_documen
YüksekCVSS 7,5Kavram kanıtıEPSS %1cpcommerce · cpcommerce20 Nis 2009
- CVE-2003-150028İzleyin
PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefi
OrtaCVSS 6,8İstismar yokEPSS %3cpcommerce · cpcommerce31 Ara 2003
- CVE-2008-190618İzleyin
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3Kavram kanıtıEPSS %2cpcommerce · cpcommerce22 Nis 2008
- CVE-2008-412117İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3İstismar yokEPSS %1cpcommerce · cpcommerce21 Eki 2008
- CVE-2007-296817İzleyin
Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web scr
OrtaCVSS 4,3İstismar yokEPSS %1cpcommerce · cpcommerce31 May 2007
- CVE-2008-463717İzleyin
Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unkno
OrtaCVSS 4,3İstismar yokEPSS %1cpcommerce · cpcommerce21 Eki 2008