VendorsVanguard Projectmarketplace_digital_products_phpall versions
Vulnerabilities

Vanguard Project Marketplace Digital Products PHP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2017-17873
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
Published 2017-12-24 · Modified
9.81 PoCEPSS 0.027
CVE-2017-17874
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
Published 2017-12-24 · Modified
8.81 PoCEPSS 0.060
CVE-2017-17936
Vanguard Marketplace Digital Products PHP has CSRF via /search.
Published 2017-12-28 · Modified
8.8EPSS 0.005
CVE-2017-17937
Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.
Published 2017-12-28 · Modified
6.1EPSS 0.006