Vulnerabilities > Website Seller Script Project

DATE CVE VULNERABILITY TITLE RISK
2019-03-21 CVE-2018-20631 Path Traversal vulnerability in Website Seller Script Project Website Seller Script 2.0.5
PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file.
network
low complexity
website-seller-script-project CWE-22
5.3
2018-12-28 CVE-2018-20530 Cross-site Scripting vulnerability in Website Seller Script Project Website Seller Script 2.0.5
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896.
network
low complexity
website-seller-script-project CWE-79
5.4
2018-08-28 CVE-2018-15897 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Website Seller Script Project Website Seller Script 2.0.5
PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, Company Name, or Fax field, as demonstrated by crossPwn.
network
low complexity
website-seller-script-project CWE-119
6.5
2018-08-28 CVE-2018-15896 Cross-site Scripting vulnerability in Website Seller Script Project Website Seller Script 2.0.5
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name.
network
low complexity
website-seller-script-project CWE-79
5.4
2018-05-26 CVE-2018-11501 Cross-site Scripting vulnerability in Website Seller Script Project Website Seller Script 2.0.3
PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
network
low complexity
website-seller-script-project CWE-79
8.8
2018-04-12 CVE-2018-6879 Improper Input Validation vulnerability in Website Seller Script Project Website Seller Script 2.0.3
PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code.
network
low complexity
website-seller-script-project CWE-20
8.8
2018-04-12 CVE-2018-6870 Cross-site Scripting vulnerability in Website Seller Script Project Website Seller Script 2.0.3
Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature.
network
low complexity
website-seller-script-project CWE-79
6.1