Show filters
215 Total Results
Displaying 211-215 of 215
Sort by:
Attacker Value
Unknown

CVE-2005-2386

Disclosure Date: July 27, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
0
Attacker Value
Unknown

CVE-2005-2207

Disclosure Date: July 11, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.
0
Attacker Value
Unknown

CVE-2005-2206

Disclosure Date: July 11, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.
0
Attacker Value
Unknown

CVE-2005-1292

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.
0
Attacker Value
Unknown

CVE-2000-1001

Disclosure Date: December 11, 2000 (last updated February 22, 2025)
add_2_basket.asp in Element InstantShop allows remote attackers to modify price information via the "price" hidden form variable.
0