Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-16614

SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php fBill parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 82.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2017-16614
  • Tp-Shop » Tpshop » Version: 2.0.5
    cpe:2.3:a:tp-shop:tpshop:2.0.5
  • Tp-Shop » Tpshop » Version: 2.0.6
    cpe:2.3:a:tp-shop:tpshop:2.0.6


Contact Us

Shodan ® - All rights reserved