PHPShop 2.1 Vulnerabilities Date: 2011.09.20 Risk: Low CVE: CVE-2010-4836 CWE: CWE-79 Affected Products Vulnerable are PHPShop 2.1 EE and previous versions (and potentially next versions). Vulnerabilities Insufficient Anti-automation (WASC-21): - Page: - Vulnerable captcha usage: - Page: - No protection against automated requests. XSS (with captcha bypass) (WASC-08): - Reference: DoS (WASC-10): - URL: Full path disclosure (WASC-13): - URL: Timeline 2010.09.08 - Announced on the site. 2010.09.11 - Informed developers. 2010.11.06 - Disclosed on the site. References Xforce ISS SecurityFocus Websecurity.com.ua SecurityFocus Archive Secunia OsVDB