Show filters
378 Total Results
Displaying 371-378 of 378
Sort by:
Attacker Value
Unknown
CVE-2004-0301
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.
0
Attacker Value
Unknown
CVE-2004-0300
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.
0
Attacker Value
Unknown
CVE-2004-2044
Disclosure Date: June 01, 2004 (last updated February 22, 2025)
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.
0
Attacker Value
Unknown
CVE-2004-2084
Disclosure Date: February 07, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.
0
Attacker Value
Unknown
CVE-2003-1219
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.
0
Attacker Value
Unknown
CVE-2003-1500
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix parameter.
0
Attacker Value
Unknown
CVE-2002-1991
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
0
Attacker Value
Unknown
CVE-2002-2019
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter.
0