phpshe kayıtları
phpshe üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2019-9762Kavram kanıtı | A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id.phpshe · phpshe · CWE-89 | Kritik9,8 | — | %6,0 | 13 Mar 2019 |
40Planlayın | CVE-2020-18020İstismar yok | SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" pphpshe · mall system · CWE-89 | Kritik9,8 | — | %3,8 | 28 Nis 2021 |
39İzleyin | CVE-2020-19165İstismar yok | PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.phpshe · phpshe · CWE-89 | Kritik9,8 | — | %1,6 | 11 Ara 2020 |
39İzleyin | CVE-2019-9626İstismar yok | PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.phpshe · phpshe · CWE-89 | Kritik9,8 | — | %1,4 | 7 Mar 2019 |
39İzleyin | CVE-2018-18486İstismar yok | An issue was discovered in PHPSHE 1.7.phpshe · phpshe · CWE-89 | Kritik9,8 | — | %1,1 | 18 Eki 2018 |
39İzleyin | CVE-2018-8943İstismar yok | There is a SQL injection in the PHPSHE 1.6 userbank parameter.phpshe · phpshe · CWE-89 | Kritik9,8 | — | %1,0 | 22 Mar 2018 |
36İzleyin | CVE-2020-18215İstismar yok | Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, whicphpshe · phpshe · CWE-89 | Yüksek8,8 | — | %2,0 | 9 Şub 2021 |
31İzleyin | CVE-2018-18485İstismar yok | An issue was discovered in PHPSHE 1.7.phpshe · phpshe · CWE-22 | Yüksek7,5 | — | %1,8 | 18 Eki 2018 |
31İzleyin | CVE-2019-9761İstismar yok | An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authenticatphpshe · phpshe · CWE-611 | Yüksek7,5 | — | %1,7 | 13 Mar 2019 |
30İzleyin | CVE-2022-24132İstismar yok | phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service.phpshe · phpshe | Yüksek7,5 | — | %1,1 | 30 Mar 2022 |
28İzleyin | CVE-2019-6708İstismar yok | PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.phpshe · phpshe · CWE-89 | Yüksek7,2 | — | %1,0 | 23 Oca 2019 |
28İzleyin | CVE-2019-6707İstismar yok | PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.phpshe · phpshe · CWE-89 | Yüksek7,2 | — | %1,0 | 23 Oca 2019 |
21İzleyin | CVE-2025-3553İstismar yok | phpshe admin.php pe_delete sql injectionphpshe · phpshe · CWE-74 | Orta5,3 | — | %0,6 | 14 Nis 2025 |
21İzleyin | CVE-2025-3554İstismar yok | phpshe api.php cross site scriptingphpshe · phpshe · CWE-79 | Orta5,3 | — | %0,5 | 14 Nis 2025 |
- CVE-2019-976241Planlayın
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id.
KritikCVSS 9,8Kavram kanıtıEPSS %6phpshe · phpshe13 Mar 2019
- CVE-2020-1802040Planlayın
SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" p
KritikCVSS 9,8İstismar yokEPSS %4phpshe · mall system28 Nis 2021
- CVE-2020-1916539İzleyin
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
KritikCVSS 9,8İstismar yokEPSS %2phpshe · phpshe11 Ara 2020
- CVE-2019-962639İzleyin
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
KritikCVSS 9,8İstismar yokEPSS %1phpshe · phpshe7 Mar 2019
- CVE-2018-1848639İzleyin
An issue was discovered in PHPSHE 1.7.
KritikCVSS 9,8İstismar yokEPSS %1phpshe · phpshe18 Eki 2018
- CVE-2018-894339İzleyin
There is a SQL injection in the PHPSHE 1.6 userbank parameter.
KritikCVSS 9,8İstismar yokEPSS %1phpshe · phpshe22 Mar 2018
- CVE-2020-1821536İzleyin
Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, whic
YüksekCVSS 8,8İstismar yokEPSS %2phpshe · phpshe9 Şub 2021
- CVE-2018-1848531İzleyin
An issue was discovered in PHPSHE 1.7.
YüksekCVSS 7,5İstismar yokEPSS %2phpshe · phpshe18 Eki 2018
- CVE-2019-976131İzleyin
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authenticat
YüksekCVSS 7,5İstismar yokEPSS %2phpshe · phpshe13 Mar 2019
- CVE-2022-2413230İzleyin
phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service.
YüksekCVSS 7,5İstismar yokEPSS %1phpshe · phpshe30 Mar 2022
- CVE-2019-670828İzleyin
PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.
YüksekCVSS 7,2İstismar yokEPSS %1phpshe · phpshe23 Oca 2019
- CVE-2019-670728İzleyin
PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.
YüksekCVSS 7,2İstismar yokEPSS %1phpshe · phpshe23 Oca 2019
- CVE-2025-355321İzleyin
phpshe admin.php pe_delete sql injection
OrtaCVSS 5,3İstismar yokEPSS %1phpshe · phpshe14 Nis 2025
- CVE-2025-355421İzleyin
phpshe api.php cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %1phpshe · phpshe14 Nis 2025