Show filters
136 Total Results
Displaying 101-110 of 136
Sort by:
Attacker Value
Unknown

CVE-2006-2165

Disclosure Date: May 04, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php and (2) prod_id parameter in (c) product_info.php. NOTE: this issue might be resultant from SQL injection.
0
Attacker Value
Unknown

CVE-2006-2164

Disclosure Date: May 04, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php, and (2) prod_id parameter in (c) cart.php and (d) product_info.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.
0
Attacker Value
Unknown

CVE-2006-2124

Disclosure Date: May 01, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php.
0
Attacker Value
Unknown

CVE-2006-2051

Disclosure Date: April 26, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters.
0
Attacker Value
Unknown

CVE-2006-0109

Disclosure Date: January 07, 2006 (last updated February 22, 2025)
Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
0
Attacker Value
Unknown

CVE-2006-0111

Disclosure Date: January 07, 2006 (last updated February 22, 2025)
Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.
0
Attacker Value
Unknown

CVE-2006-0099

Disclosure Date: January 06, 2006 (last updated February 22, 2025)
PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.
0
Attacker Value
Unknown

CVE-2005-4787

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in the code makes it easier for us to troubleshoot when issues arise on individual carts. For someone to have a script to do this type of search would require that they know where your shop is actually located. I dont think it really can be construde [sic] as a security issue.
0
Attacker Value
Unknown

CVE-2005-4571

Disclosure Date: December 29, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2005-4572

Disclosure Date: December 29, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0