Show filters
136 Total Results
Displaying 51-60 of 136
Sort by:
Attacker Value
Unknown

CVE-2009-4689

Disclosure Date: March 10, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown

CVE-2009-4688

Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid parameters.
0
Attacker Value
Unknown

CVE-2008-6969

Disclosure Date: August 13, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in checkout.php in Avactis Shopping Cart 1.8.0 and 1.8.1 allow remote attackers to inject arbitrary web script or HTML via the (1) step_id and (2) CHECKOUT_CZ_BLOWFISH_KEY parameters.
0
Attacker Value
Unknown

CVE-2009-1447

Disclosure Date: April 27, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.
0
Attacker Value
Unknown

CVE-2008-6500

Disclosure Date: March 20, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
0
Attacker Value
Unknown

CVE-2008-6278

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers to inject arbitrary web script or HTML via the (1) category_id and (2) subcategory_id parameters.
0
Attacker Value
Unknown

CVE-2008-6277

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter.
0
Attacker Value
Unknown

CVE-2008-6279

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2009-0412

Disclosure Date: February 03, 2009 (last updated October 04, 2023)
The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.
0
Attacker Value
Unknown

CVE-2009-0381

Disclosure Date: February 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.
0