Show filters
378 Total Results
Displaying 251-260 of 378
Sort by:
Attacker Value
Unknown

CVE-2018-18573

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
0
Attacker Value
Unknown

CVE-2019-14796

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.
Attacker Value
Unknown

CVE-2019-11519

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.
0
Attacker Value
Unknown

CVE-2019-7441

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state
0
Attacker Value
Unknown

CVE-2019-9168

Disclosure Date: February 26, 2019 (last updated November 27, 2024)
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
0
Attacker Value
Unknown

CVE-2019-9065

Disclosure Date: February 23, 2019 (last updated November 27, 2024)
PHP Scripts Mall Custom T-Shirt Ecommerce Script 3.1.1 allows parameter tampering of the payment amount.
0
Attacker Value
Unknown

CVE-2018-20714

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.
0
Attacker Value
Unknown

CVE-2017-18356

Disclosure Date: January 15, 2019 (last updated October 18, 2024)
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.
0
Attacker Value
Unknown

CVE-2018-18964

Disclosure Date: November 06, 2018 (last updated November 27, 2024)
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several extensions in which contained HTML can be executed, such as the svg extension.
0
Attacker Value
Unknown

CVE-2018-18965

Disclosure Date: November 06, 2018 (last updated November 27, 2024)
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename).
0