Show filters
136 Total Results
Displaying 41-50 of 136
Sort by:
Attacker Value
Unknown
CVE-2013-2705
Disclosure Date: May 13, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings.
0
Attacker Value
Unknown
CVE-2014-1618
Disclosure Date: January 21, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) p_id parameter to products.php or id parameter to (3) page.php or (4) news.php.
0
Attacker Value
Unknown
CVE-2011-5198
Disclosure Date: September 23, 2012 (last updated October 05, 2023)
SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-4147
Disclosure Date: November 02, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Pentasoft Avactis Shopping Cart 1.9.1 build 8356 free edition and earlier allow remote attackers to execute arbitrary SQL commands via the User-Agent header to (1) index.php and (2) product-list.php.
0
Attacker Value
Unknown
CVE-2010-3465
Disclosure Date: September 17, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.
0
Attacker Value
Unknown
CVE-2010-1876
Disclosure Date: May 12, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action.
0
Attacker Value
Unknown
CVE-2009-4856
Disclosure Date: May 11, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web script or HTML via the name parameter.
0
Attacker Value
Unknown
CVE-2010-1588
Disclosure Date: April 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the Getwebsess function in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via the websess parameter.
0
Attacker Value
Unknown
CVE-2010-1590
Disclosure Date: April 28, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to inject arbitrary web script or HTML via the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions.
0
Attacker Value
Unknown
CVE-2010-1589
Disclosure Date: April 28, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of arbitrary files via directory traversal sequences in the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions.
0