Filtered by vendor Advance B2b Script Project
Subscribe
Filtered by product Advance B2b Script
Subscribe
Total
5 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-20634 | 1 Advance B2b Script Project | 1 Advance B2b Script | 2019-03-21 | 4.0 MEDIUM | 6.5 MEDIUM |
PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) via JavaScript code in the First Name field. | |||||
CVE-2018-20633 | 1 Advance B2b Script Project | 1 Advance B2b Script | 2019-03-21 | 6.8 MEDIUM | 8.8 HIGH |
PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. | |||||
CVE-2018-20632 | 1 Advance B2b Script Project | 1 Advance B2b Script | 2019-03-21 | 3.5 LOW | 5.4 MEDIUM |
PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field. | |||||
CVE-2018-20635 | 1 Advance B2b Script Project | 1 Advance B2b Script | 2019-03-21 | 4.0 MEDIUM | 4.3 MEDIUM |
PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. | |||||
CVE-2017-17602 | 1 Advance B2b Script Project | 1 Advance B2b Script | 2017-12-26 | 7.5 HIGH | 9.8 CRITICAL |
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter. |