Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown
CVE-2024-4826
Disclosure Date: May 16, 2024 (last updated May 17, 2024)
SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id parameter in the category.php file.
0
Attacker Value
Unknown
CVE-2023-43274
Disclosure Date: September 21, 2023 (last updated February 25, 2025)
Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.
0
Attacker Value
Unknown
CVE-2021-30134
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
0
Attacker Value
Unknown
CVE-2021-46024
Disclosure Date: January 23, 2022 (last updated February 23, 2025)
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
0
Attacker Value
Unknown
CVE-2021-43158
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
0
Attacker Value
Unknown
CVE-2021-43157
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
0
Attacker Value
Unknown
CVE-2010-2040
Disclosure Date: May 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter.
0
Attacker Value
Unknown
CVE-2009-4856
Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web script or HTML via the name parameter.
0
Attacker Value
Unknown
CVE-2009-4689
Disclosure Date: March 10, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown
CVE-2009-4688
Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid parameters.
0