Vulnerabilities > Vice > Webopac

DATE CVE VULNERABILITY TITLE RISK
2024-11-11 CVE-2024-11020 SQL Injection vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
network
low complexity
vice CWE-89
critical
9.8
2024-11-11 CVE-2024-11021 Cross-site Scripting vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability.
network
low complexity
vice CWE-79
5.4
2024-11-11 CVE-2024-11016 SQL Injection vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
network
low complexity
vice CWE-89
critical
9.8
2024-11-11 CVE-2024-11017 Unrestricted Upload of File with Dangerous Type vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.
network
low complexity
vice CWE-434
8.8
2024-11-11 CVE-2024-11018 Unrestricted Upload of File with Dangerous Type vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.
network
low complexity
vice CWE-434
critical
9.8
2024-11-11 CVE-2024-11019 Cross-site Scripting vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.
network
low complexity
vice CWE-79
6.1
2021-11-15 CVE-2021-42838 Cross-site Scripting vulnerability in Vice Webopac 1.8.20160701/7.1.20160701
Grand Vice info Co.
network
low complexity
vice CWE-79
6.1
2021-11-15 CVE-2021-42839 Unrestricted Upload of File with Dangerous Type vulnerability in Vice Webopac 1.8.20160701/7.1.20160701
Grand Vice info Co.
network
low complexity
vice CWE-434
8.8