Smartwin Technology
smartwin_technology
4 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Smartwin Technology 1Cyberoffice Warehouse Builder Apr 16, 2026 May 4, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm. |
1Smartwin Technology 1Cyberoffice Warehouse Builder Apr 16, 2026 May 4, 2006 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3)...Show more |
1Smartwin Technology 1Cyberoffice Shopping Cart Apr 16, 2026 Dec 19, 2000 N/A· v4 N/A· v3 7.5 HIGH· v2 SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable. |
1Smartwin Technology 1Cyberoffice Shopping Cart Apr 16, 2026 Dec 19, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information. |