Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown

CVE-2018-1000640

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsanitised within JS function in the template that can result in Unauthorised actions and access to data, stealing session information, denial of service. This attack appear to be exploitable via Malicious input passed in GET parameter.
0
Attacker Value
Unknown

CVE-2018-13067

Disclosure Date: July 02, 2018 (last updated November 26, 2024)
/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's password.
0
Attacker Value
Unknown

CVE-2018-11494

Disclosure Date: May 26, 2018 (last updated November 26, 2024)
The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory name (containing 10 random digits) via a directory traversal attack involving language_info['code'].
0
Attacker Value
Unknown

CVE-2018-11495

Disclosure Date: May 26, 2018 (last updated November 26, 2024)
OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the download_id. For example, an attacker can download ../../config.php.
0
Attacker Value
Unknown

CVE-2014-3990

Disclosure Date: March 20, 2018 (last updated November 26, 2024)
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP object, related to the quantity parameter in an update request.
0
Attacker Value
Unknown

CVE-2016-10509

Disclosure Date: August 31, 2017 (last updated November 26, 2024)
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.
0
Attacker Value
Unknown

CVE-2015-4671

Disclosure Date: January 12, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id parameter to index.php.
0
Attacker Value
Unknown

CVE-2011-3763

Disclosure Date: September 24, 2011 (last updated October 04, 2023)
OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files.
0
Attacker Value
Unknown

CVE-2010-1610

Disclosure Date: April 29, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application administrator for requests that create an administrative account via a POST request with the route parameter set to "user/user/insert." NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-0956

Disclosure Date: March 10, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.
0