Show filters
87 Total Results
Displaying 61-70 of 87
Sort by:
Attacker Value
Unknown
CVE-2017-17952
Disclosure Date: December 28, 2017 (last updated November 26, 2024)
PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
0
Attacker Value
Unknown
CVE-2017-17955
Disclosure Date: December 28, 2017 (last updated November 26, 2024)
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.
0
Attacker Value
Unknown
CVE-2017-17624
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
0
Attacker Value
Unknown
CVE-2017-7723
Disclosure Date: April 24, 2017 (last updated November 26, 2024)
XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.
0
Attacker Value
Unknown
CVE-2015-1476
Disclosure Date: February 04, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL commands via the (1) productbycat parameter to product.php, or (2) username or (3) password parameter to __admin/index.php.
0
Attacker Value
Unknown
CVE-2013-6034
Disclosure Date: February 04, 2014 (last updated October 05, 2023)
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals has hardcoded credentials, which makes it easier for attackers to obtain unspecified login access via unknown vectors.
0
Attacker Value
Unknown
CVE-2013-6035
Disclosure Date: February 04, 2014 (last updated October 05, 2023)
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary code via unspecified protocol operations.
0
Attacker Value
Unknown
CVE-2013-7276
Disclosure Date: January 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in inc/raf_form.php in the Recommend to a friend plugin 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the current_url parameter.
0
Attacker Value
Unknown
CVE-2013-2506
Disclosure Date: March 08, 2013 (last updated October 05, 2023)
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.
0
Attacker Value
Unknown
CVE-2013-1656
Disclosure Date: March 08, 2013 (last updated October 05, 2023)
Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/controllers/spree/admin/payment_methods_controller.rb; and the (2) promotion_action parameter to promotion_actions_controller.rb, (3) promotion_rule parameter to promotion_rules_controller.rb, and (4) calculator_type parameter to promotions_controller.rb in promo/app/controllers/spree/admin/, related to unsafe use of the constantize function.
0