Show filters
378 Total Results
Displaying 341-350 of 378
Sort by:
Attacker Value
Unknown

CVE-2007-4121

Disclosure Date: August 01, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-2968

Disclosure Date: June 01, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter (Full Name field).
0
Attacker Value
Unknown

CVE-2007-2959

Disclosure Date: May 31, 2007 (last updated October 04, 2023)
SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter.
0
Attacker Value
Unknown

CVE-2007-2890

Disclosure Date: May 30, 2007 (last updated October 04, 2023)
SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id_category parameter.
0
Attacker Value
Unknown

CVE-2007-1477

Disclosure Date: March 16, 2007 (last updated November 08, 2023)
Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation
0
Attacker Value
Unknown

CVE-2007-1423

Disclosure Date: March 13, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts.
0
Attacker Value
Unknown

CVE-2007-1126

Disclosure Date: February 27, 2007 (last updated March 20, 2024)
Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
0
Attacker Value
Unknown

CVE-2007-0232

Disclosure Date: January 13, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.
0
Attacker Value
Unknown

CVE-2006-6533

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arbitrary PHP files via a .. (dot dot) in the filter parameter. NOTE: this issue can be leveraged to obtain full path information in error messages.
0
Attacker Value
Unknown

CVE-2006-6534

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 3.0a3 allow remote attackers to inject arbitrary web script or HTML via the (1) set parameter to admin/modules.php, the (2) selected_box parameter to definitiva/admin/customers.php, the (3) lID parameter to admin/languages_definitions.php, or the (4) pID parameter to admin/products.php.
0