Show filters
136 Total Results
Displaying 71-80 of 136
Sort by:
Attacker Value
Unknown

CVE-2008-1076

Disclosure Date: February 29, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-5364

Disclosure Date: October 11, 2007 (last updated November 08, 2023)
Directory traversal vulnerability in payments/ideal_process.php in the iDEAL transaction handler in ViArt Shopping Cart allows remote attackers to have an unknown impact via directory traversal sequences in the filename parameter to the createCertFingerprint function. NOTE: this issue is disputed by CVE because PHP encounters a fatal function-call error on a direct request for payments/ideal_process.php
0
Attacker Value
Unknown

CVE-2007-4736

Disclosure Date: September 06, 2007 (last updated October 04, 2023)
SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
0
Attacker Value
Unknown

CVE-2007-4597

Disclosure Date: August 30, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549.
0
Attacker Value
Unknown

CVE-2007-4121

Disclosure Date: August 01, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-3446

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.
0
Attacker Value
Unknown

CVE-2007-3447

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.
0
Attacker Value
Unknown

CVE-2007-3448

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.
0
Attacker Value
Unknown

CVE-2007-2997

Disclosure Date: June 04, 2007 (last updated November 08, 2023)
Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo on the website but not on the released product.
0
Attacker Value
Unknown

CVE-2007-2790

Disclosure Date: May 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the type parameter.
0