Lucene search

K

Tp-shop Security Vulnerabilities

cve
cve

CVE-2017-16614

SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php fBill parameter.

9.8CVSS

9.6AI Score

0.003EPSS

2018-03-30 09:29 PM
27
cve
cve

CVE-2018-9919

A web-accessible backdoor, with resultant SSRF, exists in Tp-shop 2.0.5 through 2.0.8, which allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution, because /vendor/phpdocumentor/reflection-docblock/tests/phpDocumentor/Reflection...

9.8CVSS

9.2AI Score

0.007EPSS

2018-05-02 09:29 PM
32
cve
cve

CVE-2020-18164

SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.

9.8CVSS

9.8AI Score

0.002EPSS

2021-08-17 08:15 PM
45
2