Show filters
378 Total Results
Displaying 241-250 of 378
Sort by:
Attacker Value
Unknown

CVE-2012-6091

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
Attacker Value
Unknown

CVE-2014-5140

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.
Attacker Value
Unknown

CVE-2019-19685

Disclosure Date: December 09, 2019 (last updated November 27, 2024)
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
Attacker Value
Unknown

CVE-2019-19683

Disclosure Date: December 09, 2019 (last updated November 27, 2024)
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs.
Attacker Value
Unknown

CVE-2019-19684

Disclosure Date: December 09, 2019 (last updated November 27, 2024)
nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.
Attacker Value
Unknown

CVE-2019-19682

Disclosure Date: December 09, 2019 (last updated November 27, 2024)
nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body or Full to Admin/News/NewsItemEdit/[id] Admin/Blog/BlogPostEdit/[id]. NOTE: the vendor reportedly considers this a "feature" because the affected components are an HTML content editor.
Attacker Value
Unknown

CVE-2016-10987

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
Attacker Value
Unknown

CVE-2019-14978

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for lower than the intended price.
0
Attacker Value
Unknown

CVE-2019-14979

Disclosure Date: August 29, 2019 (last updated November 08, 2023)
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state
0
Attacker Value
Unknown

CVE-2018-18572

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-related extensions (such as .phtml and .php5) didn't execute in the application. But this filter didn't prevent the '.pht' extension. Thus, remote authenticated administrators can upload '.pht' files for arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
0