Show filters
378 Total Results
Displaying 261-270 of 378
Sort by:
Attacker Value
Unknown

CVE-2018-18966

Disclosure Date: November 06, 2018 (last updated November 27, 2024)
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.
0
Attacker Value
Unknown

CVE-2018-8710

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function accessible to anyone without any authentication. WordPress shortcode markup in the "shortcode" parameters would be evaluated. Normally unauthenticated users can't evaluate shortcodes as they are often sensitive.
0
Attacker Value
Unknown

CVE-2018-8711

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The vulnerability is due to the lack of args/input validation on render_html before allowing it to be called by extract(), a PHP built-in function. Because of this, the supplied args/input can be used to overwrite the $pagepath variable, which then could lead to a local file inclusion attack.
0
Attacker Value
Unknown

CVE-2015-2329

Disclosure Date: February 08, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.
0
Attacker Value
Unknown

CVE-2017-17956

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.
0
Attacker Value
Unknown

CVE-2017-17957

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.
0
Attacker Value
Unknown

CVE-2017-17960

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.
0
Attacker Value
Unknown

CVE-2017-17959

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.
0
Attacker Value
Unknown

CVE-2017-17953

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.
0
Attacker Value
Unknown

CVE-2017-17958

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.
0