Vendor CVEs
Php Scripts Mall
All CVEs
32 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17641 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter. | ||
| CVE-2017-17634 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | ||
| CVE-2017-17628 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | ||
| CVE-2017-17625 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Professional Service Script 1.0 has SQL Injection via the service-list city parameter. | ||
| CVE-2017-17624 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. | ||
| CVE-2017-17959 | Cri | 0.64 | 9.8 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter. | ||
| CVE-2017-17957 | Cri | 0.64 | 9.8 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter. | ||
| CVE-2017-17951 | Cri | 0.64 | 9.8 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter. | ||
| CVE-2017-17931 | Cri | 0.64 | 9.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter. | ||
| CVE-2017-17928 | Cri | 0.64 | 9.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter. | ||
| CVE-2017-17960 | Hig | 0.57 | 8.8 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php. | ||
| CVE-2017-17939 | Hig | 0.57 | 8.8 | 0.00 | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php. | ||
| CVE-2017-17930 | Hig | 0.57 | 8.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel. | ||
| CVE-2017-17908 | Hig | 0.57 | 8.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general. | ||
| CVE-2017-17952 | Hig | 0.56 | 8.6 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address. | ||
| CVE-2017-17941 | Hig | 0.47 | 7.2 | 0.00 | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter. | ||
| CVE-2017-17958 | Med | 0.40 | 6.1 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter. | ||
| CVE-2017-17956 | Med | 0.40 | 6.1 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter. | ||
| CVE-2017-17955 | Med | 0.40 | 6.1 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter. | ||
| CVE-2017-17954 | Med | 0.40 | 6.1 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter. | ||
| CVE-2017-17953 | Med | 0.40 | 6.1 | 0.00 | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter. | ||
| CVE-2017-17927 | Med | 0.34 | 5.3 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to service-list/category/. | ||
| CVE-2017-17926 | Med | 0.34 | 5.3 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address. | ||
| CVE-2017-17924 | Med | 0.34 | 5.3 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php. | ||
| CVE-2017-17940 | Med | 0.31 | 4.8 | 0.00 | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php. | ||
| CVE-2017-17938 | Med | 0.31 | 4.8 | 0.00 | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter. | ||
| CVE-2017-17929 | Med | 0.31 | 4.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter. | ||
| CVE-2017-17925 | Med | 0.31 | 4.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter. | ||
| CVE-2017-17909 | Med | 0.31 | 4.8 | 0.00 | Dec 27, 2017 | PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter. | ||
| CVE-2019-1010028 | 0.00 | — | 0.00 | Jul 15, 2019 | phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is:… | |||
| CVE-2018-20639 | 0.00 | — | 0.00 | Mar 20, 2019 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar. | |||
| CVE-2018-20634 | 0.00 | — | 0.01 | Mar 20, 2019 | PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) via JavaScript code in the First Name field. |
- risk 0.67cvss 9.8epss 0.03
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
- risk 0.67cvss 9.8epss 0.03
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
- risk 0.67cvss 9.8epss 0.02
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
- risk 0.67cvss 9.8epss 0.03
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
- risk 0.64cvss 9.8epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.
- risk 0.64cvss 9.8epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.
- risk 0.64cvss 9.8epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.
- risk 0.64cvss 9.8epss 0.00
PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.
- risk 0.64cvss 9.8epss 0.00
PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.
- risk 0.57cvss 8.8epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.
- risk 0.57cvss 8.8epss 0.00
PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.
- risk 0.57cvss 8.8epss 0.00
PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.
- risk 0.57cvss 8.8epss 0.00
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.
- risk 0.56cvss 8.6epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
- risk 0.47cvss 7.2epss 0.00
PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter.
- risk 0.40cvss 6.1epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.
- risk 0.40cvss 6.1epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.
- risk 0.40cvss 6.1epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.
- risk 0.40cvss 6.1epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter.
- risk 0.40cvss 6.1epss 0.00
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.
- risk 0.34cvss 5.3epss 0.00
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to service-list/category/.
- risk 0.34cvss 5.3epss 0.00
PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
- risk 0.34cvss 5.3epss 0.00
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.
- risk 0.31cvss 4.8epss 0.00
PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.
- CVE-2019-1010028Jul 15, 2019risk 0.00cvss —epss 0.00
phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is:…
- CVE-2018-20639Mar 20, 2019risk 0.00cvss —epss 0.00
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar.
- CVE-2018-20634Mar 20, 2019risk 0.00cvss —epss 0.01
PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) via JavaScript code in the First Name field.