RSS   Vulnerabilities for 'Advance b2b script'   RSS

2019-03-21
 
CVE-2018-20635

CWE-22
 

 
PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.

 
 
CVE-2018-20634

CWE-119
 

 
PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) via JavaScript code in the First Name field.

 
 
CVE-2018-20633

CWE-352
 

 
PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

 
 
CVE-2018-20632

CWE-79
 

 
PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field.

 
2017-12-13
 
CVE-2017-17602

CWE-89
 

 
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top