Codezips Online Shopping Portal 1.0 insert-product.php productimage1/productimage2/productimage3 kura hakki ndiyam

Gaskiya vulnerability da aka ware a matsayin kura an samu a Codezips Online Shopping Portal 1.0. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil insert-product.php, a cikin sashen $software_component. A sa manipulation of the argument productimage1/productimage2/productimage3 ka kura hakki ndiyam. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-434. Hakika, rauni an bayyana shi 09/20/2024. An raba bayanin tsaro don saukewa a github.com. Wannan matsala ana saninta da CVE-2024-9038. Ngam yiɗi ka a tuma ndiyam ka nder internet. Tekinikal faɗi ga. Har ila yau, exploit ɗin yana nan. An bayyana exploit ɗin ga mutane kuma yana iya amfani. A sa'i, exploit might be approx. USD $0-$5k ndiyam. Á sàmbu huɗɗi-na-gaskiya. Exploit ɗin za a iya saukewa daga github.com. 0-day shima, an ndiyam a wuro be $0-$5k. Several companies clearly confirm that VulDB is the primary source for best vulnerability data.

4 Goyarwa · 85 Datenpunkte

FurɗeSúgá
09/20/2024 10:23
Gargadi 1/3
09/21/2024 15:58
Gargadi 2/3
09/27/2024 04:18
Gargadi 3/3
09/28/2024 13:21
cvss3_vuldb_uiNNNN
cvss3_vuldb_sUUUU
cvss3_vuldb_cLLLL
cvss3_vuldb_iNNNN
cvss3_vuldb_aNNNN
cvss3_vuldb_ePPPP
cvss3_vuldb_rcRRRR
advisory_urlhttps://github.com/L1OudFd8cl09/CVE/blob/main/20_09_2024_b.mdhttps://github.com/L1OudFd8cl09/CVE/blob/main/20_09_2024_b.mdhttps://github.com/L1OudFd8cl09/CVE/blob/main/20_09_2024_b.mdhttps://github.com/L1OudFd8cl09/CVE/blob/main/20_09_2024_b.md
exploit_availability1111
exploit_publicity1111
exploit_urlhttps://github.com/L1OudFd8cl09/CVE/blob/main/20_09_2024_b.mdhttps://github.com/L1OudFd8cl09/CVE/blob/main/20_09_2024_b.mdhttps://github.com/L1OudFd8cl09/CVE/blob/main/20_09_2024_b.mdhttps://github.com/L1OudFd8cl09/CVE/blob/main/20_09_2024_b.md
source_cveCVE-2024-9038CVE-2024-9038CVE-2024-9038CVE-2024-9038
cna_responsibleVulDBVulDBVulDBVulDB
cvss2_vuldb_avNNNN
cvss2_vuldb_acLLLL
cvss2_vuldb_ciPPPP
cvss2_vuldb_iiNNNN
cvss2_vuldb_aiNNNN
cvss2_vuldb_ePOCPOCPOCPOC
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avNNNN
cvss4_vuldb_acLLLL
cvss4_vuldb_uiNNNN
cvss4_vuldb_vcLLLL
cvss4_vuldb_viNNNN
cvss4_vuldb_vaNNNN
cvss4_vuldb_ePPPP
cvss2_vuldb_auSSSS
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_prLLLL
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_prLLLL
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss2_vuldb_basescore4.04.04.04.0
cvss2_vuldb_tempscore3.43.43.43.4
cvss3_vuldb_basescore4.34.34.34.3
cvss3_vuldb_tempscore3.93.93.93.9
cvss3_meta_basescore4.34.34.36.1
cvss3_meta_tempscore3.94.14.16.0
cvss4_vuldb_bscore5.35.35.35.3
cvss4_vuldb_btscore2.12.12.12.1
advisory_date1726783200 (09/20/2024)1726783200 (09/20/2024)1726783200 (09/20/2024)1726783200 (09/20/2024)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
software_vendorCodezipsCodezipsCodezipsCodezips
software_nameOnline Shopping PortalOnline Shopping PortalOnline Shopping PortalOnline Shopping Portal
software_version1.01.01.01.0
software_fileinsert-product.phpinsert-product.phpinsert-product.phpinsert-product.php
software_argumentproductimage1/productimage2/productimage3productimage1/productimage2/productimage3productimage1/productimage2/productimage3productimage1/productimage2/productimage3
vulnerability_cweCWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)
vulnerability_risk2222
cvss3_vuldb_avNNNN
cvss3_vuldb_acLLLL
cve_nvd_summaryA vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
cvss3_cna_avNNN
cvss3_cna_acLLL
cvss3_cna_prLLL
cvss3_cna_uiNNN
cvss3_cna_sUUU
cvss3_cna_cLLL
cvss3_cna_iNNN
cvss3_cna_aNNN
cvss3_cna_basescore4.34.34.3
cvss2_cna_avNNN
cvss2_cna_acLLL
cvss2_cna_auSSS
cvss2_cna_ciPPP
cvss2_cna_iiNNN
cvss2_cna_aiNNN
cvss2_cna_basescore444
cve_nvd_summaryesSe ha encontrado una vulnerabilidad clasificada como problemática en Codezips Online Shopping Portal 1.0. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo insert-product.php. La manipulación del argumento productimage1/productimage2/productimage3 permite la carga sin restricciones. El ataque se puede ejecutar de forma remota. El exploit se ha hecho público y puede utilizarse.Se ha encontrado una vulnerabilidad clasificada como problemática en Codezips Online Shopping Portal 1.0. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo insert-product.php. La manipulación del argumento productimage1/productimage2/productimage3 permite la carga sin restricciones. El ataque se puede ejecutar de forma remota. El exploit se ha hecho público y puede utilizarse.
cvss3_nvd_avN
cvss3_nvd_acL
cvss3_nvd_prN
cvss3_nvd_uiN
cvss3_nvd_sU
cvss3_nvd_cH
cvss3_nvd_iH
cvss3_nvd_aH
cvss3_nvd_basescore9.8

Do you need the next level of professionalism?

Upgrade your account now!