Smartwin Technology maintains a narrow product line centered on e-commerce platforms such as CyberOffice Shopping Cart and CyberOffice Warehouse Builder, both web-facing applications handling customer transactions and product data. The vendor's vulnerability exposure recurs through web-application input-handling issues, particularly cross-site scripting flaws that affect the interactive elements of these platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartwin Technology over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0926HIGH SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable. | Dec 19, 2000 | 7.5 | 31 | NO | YES |
CVE-2006-2179HIGH Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex param | May 4, 2006 | 7.5 | 29 | NO | YES |
CVE-2000-0925MEDIUM The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to o | Dec 19, 2000 | 5.0 | 25 | NO | YES |
CVE-2006-2178MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) Pr | May 4, 2006 | 5.8 | 24 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartwin Technology.
Media articles that mention a CVE ID that affects a product developed by Smartwin Technology — matched by CVE ID, not by vendor name.