Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Php Multivendor Ecommerce CRITICAL 9.8
CVE-2017-17951

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.

No fix yet
Fix from $2,300 2017-12-28
Php Multivendor Ecommerce CRITICAL 9.8
CVE-2017-17957

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.

No fix yet
Fix from $2,300 2017-12-28
Php Multivendor Ecommerce CRITICAL 9.8
CVE-2017-17959

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.

No fix yet
Fix from $2,300 2017-12-28
Php Multivendor Ecommerce HIGH 8.8
CVE-2017-17960

PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.

No fix yet
Fix from $1,950 2017-12-28
Php Multivendor Ecommerce HIGH 8.6
CVE-2017-17952

PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid …

No fix yet
Fix from $1,950 2017-12-28
Php Multivendor Ecommerce MEDIUM 6.1
CVE-2017-17953

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.

No fix yet
Fix from $1,600 2017-12-28
Php Multivendor Ecommerce MEDIUM 6.1
CVE-2017-17954

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter.

No fix yet
Fix from $1,600 2017-12-28
Php Multivendor Ecommerce MEDIUM 6.1
CVE-2017-17955

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.

No fix yet
Fix from $1,600 2017-12-28
Php Multivendor Ecommerce MEDIUM 6.1
CVE-2017-17956

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.

No fix yet
Fix from $1,600 2017-12-28
Php Multivendor Ecommerce MEDIUM 6.1
CVE-2017-17958

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.

No fix yet
Fix from $1,600 2017-12-28
Php Multivendor Ecommerce CRITICAL 9.8
CVE-2017-17624

PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.

No fix yet
Fix from $2,300 2017-12-13