Professional Service Script
Vendor:
First CVE: Dec 27, 2017 · Active for 8 years
7
Total CVEs
More Total CVEs than 83% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Professional Service Script over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2017
8 years ago
Most Recent CVE
Dec 27, 2017
3,131 days ago
CVE Severity & Scoring
Professional Service Script7 CVEs
71%
14%
14%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (57.1%)
Unknown0 (0.0%)
Required3 (42.9%)
Privileges Required
Low0 (0.0%)
High2 (28.6%)
None5 (71.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17928CRITICAL PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter. | Dec 27, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-17930HIGH PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel. | Dec 27, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-17927MEDIUM PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to service-list/category/. | Dec 27, 2017 | 5.3 | 19 | NO | NO |
CVE-2017-17924MEDIUM PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php. | Dec 27, 2017 | 5.3 | 19 | NO | NO |
CVE-2017-17929MEDIUM PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter. | Dec 27, 2017 | 4.8 | 18 | NO | NO |
CVE-2017-17926MEDIUM PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address. | Dec 27, 2017 | 5.3 | 18 | NO | NO |
CVE-2017-17925MEDIUM PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter. | Dec 27, 2017 | 4.8 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Professional Service Script
Top CWEs
Versions
No cataloged versions.