Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown
CVE-2013-7317
Disclosure Date: January 24, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) settings_file or (2) data_file parameter to (a) ampie.swf, (b) amline.swf, or (c) amcolumn.swf.
0
Attacker Value
Unknown
CVE-2013-0118
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
0
Attacker Value
Unknown
CVE-2009-4891
Disclosure Date: June 11, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a products.view action.
0
Attacker Value
Unknown
CVE-2009-2579
Disclosure Date: August 05, 2009 (last updated October 04, 2023)
SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2.
0
Attacker Value
Unknown
CVE-2008-6394
Disclosure Date: March 04, 2009 (last updated October 04, 2023)
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.
0
Attacker Value
Unknown
CVE-2008-1458
Disclosure Date: March 24, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in CS-Cart 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a products search action. NOTE: it was also reported that 1.3.5-SP2 trial edition is also affected.
0
Attacker Value
Unknown
CVE-2007-0230
Disclosure Date: January 13, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter. NOTE: CVE and third parties dispute this vulnerability because install_dir is defined before use
0
Attacker Value
Unknown
CVE-2006-5962
Disclosure Date: November 17, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
0
Attacker Value
Unknown
CVE-2006-2863
Disclosure Date: June 06, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.
0
Attacker Value
Unknown
CVE-2005-4429
Disclosure Date: December 21, 2005 (last updated February 22, 2025)
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.
0