Known Vulnerabilities for products from Phpshe
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Phpshe".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-24132 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2022-03-30 | 2022-04-07 |
| CVE-2020-19165 json | PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter. | 9.8 - CRITICAL | 2020-12-11 | 2020-12-14 |
| CVE-2020-18215 json | Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id p... | 8.8 - HIGH | 2021-02-09 | 2021-02-12 |
| CVE-2020-18020 json | SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the... | 9.8 - CRITICAL | 2021-04-28 | 2021-05-05 |
| CVE-2019-9762 json | A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerabilit... | 9.8 - CRITICAL | 2019-03-14 | 2019-03-14 |
| CVE-2019-9761 json | An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network with... | 7.5 - HIGH | 2019-03-14 | 2019-03-14 |
| CVE-2019-9626 json | PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php. | 9.8 - CRITICAL | 2019-03-07 | 2019-03-07 |
| CVE-2019-6708 json | PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter. | 7.2 - HIGH | 2019-01-23 | 2020-08-24 |
| CVE-2019-6707 json | PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter. | 7.2 - HIGH | 2019-01-23 | 2020-08-24 |
| CVE-2018-18486 json | An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter. | 9.8 - CRITICAL | 2018-10-18 | 2018-12-03 |
| CVE-2018-18485 json | An issue was discovered in PHPSHE 1.7. admin.php?mod=db&act=del allows remote attackers to delete arbitrary files via directo... | 7.5 - HIGH | 2018-10-18 | 2019-01-08 |
| CVE-2018-8943 json | There is a SQL injection in the PHPSHE 1.6 userbank parameter. | 9.8 - CRITICAL | 2018-03-22 | 2018-04-18 |
Known software with vulnerabilities from Phpshe
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Phpshe | Phpshe | 1.6 |