CVE-2025-3554
- EPSS 0.2%
- Veröffentlicht 14.04.2025 06:31:07
- Zuletzt bearbeitet 10.10.2025 17:16:19
A vulnerability was found in phpshe 1.8. It has been rated as problematic. This issue affects some unknown processing of the file api.php?mod=cron&act=buyer. The manipulation of the argument act leads to cross site scripting. The attack may be initia...
CVE-2025-3553
- EPSS 0.22%
- Veröffentlicht 14.04.2025 06:00:15
- Zuletzt bearbeitet 10.10.2025 17:17:28
A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_delete of the file /admin.php?mod=brand&act=del. The manipulation of the argument brand_id[] leads to sql injection. The attack can ...
CVE-2022-24132
- EPSS 0.33%
- Veröffentlicht 30.03.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:49:52
phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service.
CVE-2020-18215
- EPSS 0.56%
- Veröffentlicht 09.02.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:08:29
Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code.
CVE-2020-19165
- EPSS 0.44%
- Veröffentlicht 11.12.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:09:00
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
CVE-2019-9761
- EPSS 0.62%
- Veröffentlicht 14.03.2019 02:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:15
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in include/plugin/payment/wechat/notify_url.php.
CVE-2019-9762
- EPSS 59.67%
- Veröffentlicht 14.03.2019 02:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:15
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.
CVE-2019-9626
- EPSS 0.25%
- Veröffentlicht 07.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:59
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
CVE-2019-6707
- EPSS 0.24%
- Veröffentlicht 23.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:46:59
PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.
CVE-2019-6708
- EPSS 0.24%
- Veröffentlicht 23.01.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:46:59
PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.