Show filters
378 Total Results
Displaying 241-250 of 378
Sort by:
Attacker Value
Unknown
CVE-2012-6091
Disclosure Date: February 13, 2020 (last updated February 21, 2025)
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2014-5140
Disclosure Date: January 03, 2020 (last updated February 21, 2025)
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.
0
Attacker Value
Unknown
CVE-2019-19685
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
0
Attacker Value
Unknown
CVE-2019-19683
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs.
0
Attacker Value
Unknown
CVE-2019-19684
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.
0
Attacker Value
Unknown
CVE-2019-19682
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body or Full to Admin/News/NewsItemEdit/[id] Admin/Blog/BlogPostEdit/[id]. NOTE: the vendor reportedly considers this a "feature" because the affected components are an HTML content editor.
0
Attacker Value
Unknown
CVE-2016-10987
Disclosure Date: September 17, 2019 (last updated November 27, 2024)
The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
0
Attacker Value
Unknown
CVE-2019-14978
Disclosure Date: August 29, 2019 (last updated November 27, 2024)
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for lower than the intended price.
0
Attacker Value
Unknown
CVE-2019-14979
Disclosure Date: August 29, 2019 (last updated November 08, 2023)
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state
0
Attacker Value
Unknown
CVE-2018-18572
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-related extensions (such as .phtml and .php5) didn't execute in the application. But this filter didn't prevent the '.pht' extension. Thus, remote authenticated administrators can upload '.pht' files for arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
0