xt-commerce kayıtları
xt-commerce üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-276 Incorrect Default Permissions1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
28İzleyin | CVE-2011-5011İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack xt-commerce · xt-commerce · CWE-352 | Orta6,8 | — | %3,3 | 24 Ara 2011 |
28İzleyin | CVE-2008-6045Kavram kanıtı | Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by settixt-commerce · xt-commerce · CWE-287 | Orta6,8 | — | %2,9 | 3 Şub 2009 |
27İzleyin | CVE-2008-6304İstismar yok | SQL injection vulnerability in xt:Commerce before 3.0.4 Sp2.1, when magic_quotes_gpc is enabled and the SEO URLs are activated, allows remotxt-commerce · xt-commerce · CWE-89 | Orta6,8 | — | %1,3 | 26 Şub 2009 |
27İzleyin | CVE-2010-1359İstismar yok | SQL injection vulnerability in bluegate_seo.inc.php in the Direct URL module for xt:Commerce, when magic_quotes_gpc is disabled, allows remobluegate · direct url · CWE-89 | Orta6,8 | — | %1,1 | 13 Nis 2010 |
22İzleyin | CVE-2007-1126Kavram kanıtı | Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a ..xt-commerce · xt-commerce · CWE-22 | Orta5,0 | — | %5,6 | 26 Şub 2007 |
18İzleyin | CVE-2020-12101İstismar yok | The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by maxt-commerce · xt-commerce · CWE-276 | Orta4,3 | — | %2,0 | 30 Nis 2020 |
18İzleyin | CVE-2008-6044Kavram kanıtı | Cross-site scripting (XSS) vulnerability in advanced_search_result.php in xt:Commerce 3.0.4 and earlier allows remote attackers to inject arxt-commerce · xt-commerce · CWE-79 | Orta4,3 | — | %1,8 | 3 Şub 2009 |
- CVE-2011-501128İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack
OrtaCVSS 6,8İstismar yokEPSS %3xt-commerce · xt-commerce24 Ara 2011
- CVE-2008-604528İzleyin
Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setti
OrtaCVSS 6,8Kavram kanıtıEPSS %3xt-commerce · xt-commerce3 Şub 2009
- CVE-2008-630427İzleyin
SQL injection vulnerability in xt:Commerce before 3.0.4 Sp2.1, when magic_quotes_gpc is enabled and the SEO URLs are activated, allows remot
OrtaCVSS 6,8İstismar yokEPSS %1xt-commerce · xt-commerce26 Şub 2009
- CVE-2010-135927İzleyin
SQL injection vulnerability in bluegate_seo.inc.php in the Direct URL module for xt:Commerce, when magic_quotes_gpc is disabled, allows remo
OrtaCVSS 6,8İstismar yokEPSS %1bluegate · direct url13 Nis 2010
- CVE-2007-112622İzleyin
Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a ..
OrtaCVSS 5,0Kavram kanıtıEPSS %6xt-commerce · xt-commerce26 Şub 2007
- CVE-2020-1210118İzleyin
The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by ma
OrtaCVSS 4,3İstismar yokEPSS %2xt-commerce · xt-commerce30 Nis 2020
- CVE-2008-604418İzleyin
Cross-site scripting (XSS) vulnerability in advanced_search_result.php in xt:Commerce 3.0.4 and earlier allows remote attackers to inject ar
OrtaCVSS 4,3Kavram kanıtıEPSS %2xt-commerce · xt-commerce3 Şub 2009