Vulnerabilities > Basic B2B Script Project

DATE CVE VULNERABILITY TITLE RISK
2019-03-21 CVE-2018-20646 Path Traversal vulnerability in Basic B2B Script Project Basic B2B Script 2.0.9
PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory.
network
low complexity
basic-b2b-script-project CWE-22
6.5
2019-03-21 CVE-2018-20645 Cross-site Scripting vulnerability in Basic B2B Script Project Basic B2B Script 2.0.9
PHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field.
network
low complexity
basic-b2b-script-project CWE-79
5.4
2019-03-21 CVE-2018-20644 Cross-Site Request Forgery (CSRF) vulnerability in Basic B2B Script Project Basic B2B Script 2.0.9
PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature.
network
low complexity
basic-b2b-script-project CWE-352
8.8
2017-12-13 CVE-2017-17600 SQL Injection vulnerability in Basic B2B Script Project Basic B2B Script 2.0.8
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
network
low complexity
basic-b2b-script-project CWE-89
critical
9.8