Show filters
378 Total Results
Displaying 331-340 of 378
Sort by:
Attacker Value
Unknown
CVE-2008-4143
Disclosure Date: September 24, 2008 (last updated October 04, 2023)
SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2008-4170
Disclosure Date: September 22, 2008 (last updated October 04, 2023)
create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2008-1908
Disclosure Date: April 22, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the language parameter in a language action to the default URI, which is not properly handled in actions/language.act.php, or (2) the action parameter to category.php.
0
Attacker Value
Unknown
CVE-2008-1906
Disclosure Date: April 22, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a view.year action.
0
Attacker Value
Unknown
CVE-2008-1907
Disclosure Date: April 22, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) id_manufacturer, and (3) id_category parameters to unspecified components. NOTE: this probably overlaps CVE-2007-2959 and CVE-2007-2890.
0
Attacker Value
Unknown
CVE-2008-1839
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
Multgiple cross-site scripting (XSS) vulnerabilities in module/main.php in WORK system e-commerce 4.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, and (3) year parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-0719
Disclosure Date: February 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter.
0
Attacker Value
Unknown
CVE-2008-0281
Disclosure Date: January 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter.
0
Attacker Value
Unknown
CVE-2007-5836
Disclosure Date: November 05, 2007 (last updated October 04, 2023)
SQL injection vulnerability in Amazing Flash AFCommerce allows remote attackers to execute arbitrary SQL commands via the firstname parameter to an unspecified component, a different issue than CVE-2006-3794. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-5801
Disclosure Date: November 03, 2007 (last updated October 04, 2023)
Unspecified vulnerability in WORK system e-commerce before 4.0.2 has unknown impact and attack vectors related to "Ajax pages."
0