Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Watersweb Shops Subscribe
Filtered by product Shop Kit Plus
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-1128 1 Watersweb Shops 1 Shop Kit Plus 2018-10-16 5.0 MEDIUM N/A
shopkitplus allows remote attackers to obtain sensitive information via a request to (1) events.php with a curmonth[]=01 query string or (2) enc/stylecss.php with a changetheme[]= query string, which reveals the path in various error messages.
CVE-2007-1127 1 Watersweb Shops 1 Shop Kit Plus 2018-10-16 6.4 MEDIUM N/A
Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.