Show filters
378 Total Results
Displaying 341-350 of 378
Sort by:
Attacker Value
Unknown
CVE-2007-4121
Disclosure Date: August 01, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-2968
Disclosure Date: June 01, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter (Full Name field).
0
Attacker Value
Unknown
CVE-2007-2959
Disclosure Date: May 31, 2007 (last updated October 04, 2023)
SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter.
0
Attacker Value
Unknown
CVE-2007-2890
Disclosure Date: May 30, 2007 (last updated October 04, 2023)
SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id_category parameter.
0
Attacker Value
Unknown
CVE-2007-1477
Disclosure Date: March 16, 2007 (last updated November 08, 2023)
Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation
0
Attacker Value
Unknown
CVE-2007-1423
Disclosure Date: March 13, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts.
0
Attacker Value
Unknown
CVE-2007-1126
Disclosure Date: February 27, 2007 (last updated March 20, 2024)
Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
0
Attacker Value
Unknown
CVE-2007-0232
Disclosure Date: January 13, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.
0
Attacker Value
Unknown
CVE-2006-6533
Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arbitrary PHP files via a .. (dot dot) in the filter parameter. NOTE: this issue can be leveraged to obtain full path information in error messages.
0
Attacker Value
Unknown
CVE-2006-6534
Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 3.0a3 allow remote attackers to inject arbitrary web script or HTML via the (1) set parameter to admin/modules.php, the (2) selected_box parameter to definitiva/admin/customers.php, the (3) lID parameter to admin/languages_definitions.php, or the (4) pID parameter to admin/products.php.
0