Show filters
32 Total Results
Displaying 31-32 of 32
Sort by:
Attacker Value
Unknown
CVE-2004-1874
Disclosure Date: March 29, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user information forms.
0
Attacker Value
Unknown
CVE-2002-1432
Disclosure Date: April 11, 2003 (last updated February 22, 2025)
MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.
0