Show filters
87 Total Results
Displaying 31-40 of 87
Sort by:
Attacker Value
Unknown
CVE-2022-35213
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php.
0
Attacker Value
Unknown
CVE-2022-30482
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar- 1.0 is vulnerable to Cross Site Scripting (XSS) in \admin\add_cata.php via the ctg_name parameters.
0
Attacker Value
Unknown
CVE-2022-30478
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.
0
Attacker Value
Unknown
CVE-2022-27357
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-27346
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-26624
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.
0
Attacker Value
Unknown
CVE-2022-27436
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.
0
Attacker Value
Unknown
CVE-2022-27435
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.
0
Attacker Value
Unknown
CVE-2021-41275
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authentication framework. In affected versions spree_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of spree_auth_devise are affected if protect_from_forgery method is both: Executed whether as: A before_action callback (the default). A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception). Users are advised to update their spree_auth_devise gem. For users unable to update it may be possible to change your strategy to :exception. Please see the linked GHSA for more wo…
0
Attacker Value
Unknown
CVE-2021-40975
Disclosure Date: October 01, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.
0