Show filters
378 Total Results
Displaying 351-360 of 378
Sort by:
Attacker Value
Unknown

CVE-2006-5190

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.
0
Attacker Value
Unknown

CVE-2006-4969

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in WAHM E-Commerce Pie Cart Pro allow remote attackers to execute arbitrary PHP code via a URL in the Inc_Dir parameter in (1) affiliates.php, (2) orders.php, (3) events.php, (4) index.php, (5) articles.php, (6) faqs.php, (7) guestbook.php, (8) catalog.php, (9) wholesale.php, (10) weblinks.php, (11) certificates.php, (12) sitesearch.php, (13) contact.php, (14) sitemap.php, (15) search.php, (16) registry.php, or (17) error.php.
0
Attacker Value
Unknown

CVE-2006-4970

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to execute arbitrary PHP code via a URL in the Home_Path parameter.
0
Attacker Value
Unknown

CVE-2006-4297

Disclosure Date: August 23, 2006 (last updated October 04, 2023)
SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQL commands via id array parameters.
0
Attacker Value
Unknown

CVE-2006-4298

Disclosure Date: August 23, 2006 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in cache.php in osCommerce before 2.2 Milestone 2 060817 allow remote attackers to determine existence of arbitrary files and disclose the installation path via a .. (dot dot) in unspecified parameters in the (1) tep_cache_also_purchased, (2) tep_cache_manufacturers_box, and (3) tep_cache_categories_box functions.
0
Attacker Value
Unknown

CVE-2006-4121

Disclosure Date: August 14, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in owimg.php3 in See-Commerce 1.0.625 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
0
Attacker Value
Unknown

CVE-2006-3794

Disclosure Date: July 24, 2006 (last updated November 08, 2023)
SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried.
0
Attacker Value
Unknown

CVE-2006-3800

Disclosure Date: July 24, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box.
0
Attacker Value
Unknown

CVE-2006-1109

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE.
0
Attacker Value
Unknown

CVE-2005-3914

Disclosure Date: November 30, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
0