← Back

Website Seller Script Project

website_seller_script_project

7 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Website Seller Script Project
1Website Seller Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file.
1Website Seller Script Project
1Website Seller Script
Nov 21, 2024
Dec 28, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896.
1Website Seller Script Project
1Website Seller Script
Nov 21, 2024
Aug 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, Company Name, or Fax field, as demonstrated by crossPwn.
1Website Seller Script Project
1Website Seller Script
Nov 21, 2024
Aug 28, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name.
1Website Seller Script Project
1Website Seller Script
Nov 21, 2024
May 26, 2018
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
1Website Seller Script Project
1Website Seller Script
Jun 17, 2026
Apr 12, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code.
1Website Seller Script Project
1Website Seller Script
Jun 17, 2026
Apr 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature.