Vulnerabilities
Vulnerable Software
Cosmoshop:  >> Cosmoshop  >> 8.10.78  Security Vulnerabilities
SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter.
CVSS Score
7.5
EPSS Score
0.005
Published
2006-05-19
Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.
CVSS Score
7.8
EPSS Score
0.007
Published
2006-05-19
SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.009
Published
2005-09-02
cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information.
CVSS Score
2.1
EPSS Score
0.001
Published
2005-09-02
Directory traversal vulnerability in bestmail_edit.cgi in cosmoshop 8.10.78 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.
CVSS Score
5.0
EPSS Score
0.004
Published
2005-09-02


Contact Us

Shodan ® - All rights reserved