Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2007-2068

Disclosure Date: April 18, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.
0
Attacker Value
Unknown

CVE-2005-0936

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown

CVE-2005-0935

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php.
0
Attacker Value
Unknown

CVE-2004-2700

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.
0
Attacker Value
Unknown

CVE-2004-2699

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.
0
Attacker Value
Unknown

CVE-2004-2701

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.
0
Attacker Value
Unknown

CVE-2003-0557

Disclosure Date: August 18, 2003 (last updated February 22, 2025)
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.
0