Vendor CVEs
Viart
All CVEs
27 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2007-6347 | 0.04 | — | 0.07 | Dec 13, 2007 | PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of… | |||
| CVE-2009-4548 | 0.03 | — | 0.02 | Jan 4, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to… | |||
| CVE-2009-4547 | 0.03 | — | 0.02 | Jan 4, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt CMS 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter to forums.php, or the forum_id parameter to (2) forum.php or (3) forum_topic_new.php. | |||
| CVE-2008-6765 | 0.03 | — | 0.02 | Apr 28, 2009 | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter. | |||
| CVE-2008-6758 | 0.03 | — | 0.01 | Apr 28, 2009 | Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a… | |||
| CVE-2008-6757 | 0.03 | — | 0.02 | Apr 28, 2009 | Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter. | |||
| CVE-2008-3369 | 0.03 | — | 0.02 | Jul 30, 2008 | SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | |||
| CVE-2006-0532 | 0.03 | — | 0.04 | Feb 4, 2006 | Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok parameter containing a javascript: URI in an IMG SRC attribute. | |||
| CVE-2005-1440 | 0.03 | — | 0.03 | May 3, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using… | |||
| CVE-2023-30090 | 0.00 | — | 0.01 | May 5, 2023 | Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file. | |||
| CVE-2021-38728 | 0.00 | — | 0.00 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php. | |||
| CVE-2021-38736 | 0.00 | — | 0.01 | Oct 28, 2022 | SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php. | |||
| CVE-2021-38733 | 0.00 | — | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php. | |||
| CVE-2021-38732 | 0.00 | — | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php. | |||
| CVE-2021-28024 | 0.00 | — | 0.01 | Nov 8, 2021 | Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password. | |||
| CVE-2021-28022 | 0.00 | — | 0.01 | Nov 8, 2021 | Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries. | |||
| CVE-2020-2500 | 0.00 | — | 0.01 | Jul 1, 2020 | This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in… | |||
| CVE-2020-11431 | 0.00 | — | 0.02 | May 7, 2020 | The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal. | |||
| CVE-2018-0728 | 0.00 | — | 0.01 | Dec 4, 2019 | This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions. | |||
| CVE-2008-6766 | 0.00 | — | 0.01 | Apr 28, 2009 | cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of service (excessive shopping carts) via a flood of requests. | |||
| CVE-2008-6760 | 0.00 | — | 0.02 | Apr 28, 2009 | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a… | |||
| CVE-2008-6759 | 0.00 | — | 0.01 | Apr 28, 2009 | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installation path in an error message. | |||
| CVE-2007-5463 | 0.00 | — | 0.01 | Oct 15, 2007 | ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attackers to obtain the pathname for certificate and key files via an "iDEAL transaction", possibly involving fopen error messages for nonexistent files, a different issue than… | |||
| CVE-2007-5364 | 0.00 | — | 0.02 | Oct 11, 2007 | Directory traversal vulnerability in payments/ideal_process.php in the iDEAL transaction handler in ViArt Shopping Cart allows remote attackers to have an unknown impact via directory traversal sequences in the filename parameter to the createCertFingerprint function. NOTE:… | |||
| CVE-2006-2979 | 0.00 | — | 0.01 | Jun 12, 2006 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter in forum.php, which is not… | |||
| CVE-2006-2980 | 0.00 | — | 0.01 | Jun 12, 2006 | SQL injection vulnerability in block_forum_topic_new.php in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, might allow remote attackers to execute arbitrary SQL commands via unknown vectors, probably involving the forum_id… | |||
| CVE-2005-4404 | 0.00 | — | 0.01 | Dec 20, 2005 | SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources. |
- CVE-2007-6347Dec 13, 2007risk 0.04cvss —epss 0.07
PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of…
- CVE-2009-4548Jan 4, 2010risk 0.03cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to…
- CVE-2009-4547Jan 4, 2010risk 0.03cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in ViArt CMS 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter to forums.php, or the forum_id parameter to (2) forum.php or (3) forum_topic_new.php.
- CVE-2008-6765Apr 28, 2009risk 0.03cvss —epss 0.02
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter.
- CVE-2008-6758Apr 28, 2009risk 0.03cvss —epss 0.01
Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a…
- CVE-2008-6757Apr 28, 2009risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter.
- CVE-2008-3369Jul 30, 2008risk 0.03cvss —epss 0.02
SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
- CVE-2006-0532Feb 4, 2006risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok parameter containing a javascript: URI in an IMG SRC attribute.
- CVE-2005-1440May 3, 2005risk 0.03cvss —epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using…
- CVE-2023-30090May 5, 2023risk 0.00cvss —epss 0.01
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2021-38728Oct 28, 2022risk 0.00cvss —epss 0.00
SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.
- CVE-2021-38736Oct 28, 2022risk 0.00cvss —epss 0.01
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
- CVE-2021-38733Oct 28, 2022risk 0.00cvss —epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
- CVE-2021-38732Oct 28, 2022risk 0.00cvss —epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
- CVE-2021-28024Nov 8, 2021risk 0.00cvss —epss 0.01
Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.
- CVE-2021-28022Nov 8, 2021risk 0.00cvss —epss 0.01
Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.
- CVE-2020-2500Jul 1, 2020risk 0.00cvss —epss 0.01
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in…
- CVE-2020-11431May 7, 2020risk 0.00cvss —epss 0.02
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
- CVE-2018-0728Dec 4, 2019risk 0.00cvss —epss 0.01
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
- CVE-2008-6766Apr 28, 2009risk 0.00cvss —epss 0.01
cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of service (excessive shopping carts) via a flood of requests.
- CVE-2008-6760Apr 28, 2009risk 0.00cvss —epss 0.02
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a…
- CVE-2008-6759Apr 28, 2009risk 0.00cvss —epss 0.01
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installation path in an error message.
- CVE-2007-5463Oct 15, 2007risk 0.00cvss —epss 0.01
ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attackers to obtain the pathname for certificate and key files via an "iDEAL transaction", possibly involving fopen error messages for nonexistent files, a different issue than…
- CVE-2007-5364Oct 11, 2007risk 0.00cvss —epss 0.02
Directory traversal vulnerability in payments/ideal_process.php in the iDEAL transaction handler in ViArt Shopping Cart allows remote attackers to have an unknown impact via directory traversal sequences in the filename parameter to the createCertFingerprint function. NOTE:…
- CVE-2006-2979Jun 12, 2006risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter in forum.php, which is not…
- CVE-2006-2980Jun 12, 2006risk 0.00cvss —epss 0.01
SQL injection vulnerability in block_forum_topic_new.php in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, might allow remote attackers to execute arbitrary SQL commands via unknown vectors, probably involving the forum_id…
- CVE-2005-4404Dec 20, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.