Show filters
136 Total Results
Displaying 61-70 of 136
Sort by:
Attacker Value
Unknown

CVE-2008-5929

Disclosure Date: January 21, 2009 (last updated October 04, 2023)
VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database containing the password via a direct request for database/shopping650.mdb. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-5838

Disclosure Date: January 05, 2009 (last updated October 04, 2023)
SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown

CVE-2008-4886

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.
0
Attacker Value
Unknown

CVE-2008-4143

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2008-3768

Disclosure Date: August 22, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an edit_registry action to index.php, (2) a vector involving the check_email function, and other vectors.
0
Attacker Value
Unknown

CVE-2008-3585

Disclosure Date: August 11, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.php and (2) store_info.php.
0
Attacker Value
Unknown

CVE-2008-2774

Disclosure Date: June 19, 2008 (last updated October 04, 2023)
SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execute arbitrary SQL commands via the category_id parameter, a different vector than CVE-2007-4736.
0
Attacker Value
Unknown

CVE-2008-2339

Disclosure Date: May 19, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Turnkey Web Tools SunShop Shopping Cart 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action, a different vector than CVE-2008-2038, CVE-2007-4597, and CVE-2007-2549.
0
Attacker Value
Unknown

CVE-2008-2038

Disclosure Date: April 30, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) orderby and (2) sort parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-1921

Disclosure Date: April 23, 2008 (last updated October 04, 2023)
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.
0