Dsmall
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-9014 | Hig | 0.49 | 7.5 | 0.01 | Mar 25, 2018 | dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request. | ||
| CVE-2018-9307 | Med | 0.40 | 6.1 | 0.01 | Apr 4, 2018 | dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html. | ||
| CVE-2018-9016 | Med | 0.40 | 6.1 | 0.01 | Mar 25, 2018 | dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI. | ||
| CVE-2018-8906 | Med | 0.40 | 6.1 | 0.01 | Mar 22, 2018 | dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html. | ||
| CVE-2018-9017 | Med | 0.35 | 5.4 | 0.01 | Mar 25, 2018 | dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI. | ||
| CVE-2018-9015 | Med | 0.35 | 5.4 | 0.01 | Mar 25, 2018 | dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box). |
- risk 0.49cvss 7.5epss 0.01
dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.
- risk 0.40cvss 6.1epss 0.01
dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html.
- risk 0.40cvss 6.1epss 0.01
dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI.
- risk 0.40cvss 6.1epss 0.01
dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html.
- risk 0.35cvss 5.4epss 0.01
dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI.
- risk 0.35cvss 5.4epss 0.01
dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).