Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Ecommerce\-Website
(Ecommerce\-Website_project)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 5 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-12-05 | CVE-2022-45990 | A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter. | Ecommerce\-Website | 6.1 | ||
2022-04-04 | CVE-2022-27435 | An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component. | Ecommerce\-Website | 8.8 | ||
2022-04-04 | CVE-2022-27436 | A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field. | Ecommerce\-Website | 4.8 | ||
2022-04-08 | CVE-2022-27346 | Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | Ecommerce\-Website | 8.8 | ||
2022-04-08 | CVE-2022-27357 | Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | Ecommerce\-Website | 9.8 |