Show filters
87 Total Results
Displaying 71-80 of 87
Sort by:
Attacker Value
Unknown

CVE-2008-7310

Disclosure Date: April 05, 2012 (last updated October 04, 2023)
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.
0
Attacker Value
Unknown

CVE-2008-7311

Disclosure Date: April 05, 2012 (last updated October 04, 2023)
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file.
0
Attacker Value
Unknown

CVE-2010-4735

Disclosure Date: February 16, 2011 (last updated October 04, 2023)
SQL injection vulnerability in shoppingcart.asp in Ecommercemax Solutions Digital-goods seller (DGS) 1.5 allows remote attackers to execute arbitrary SQL commands via the d parameter.
0
Attacker Value
Unknown

CVE-2010-3978

Disclosure Date: November 17, 2010 (last updated October 04, 2023)
Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/products.json, (2) admin/users.json, or (3) admin/overview/get_report_data, related to a "JSON hijacking" issue.
0
Attacker Value
Unknown

CVE-2010-3465

Disclosure Date: September 17, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.
0
Attacker Value
Unknown

CVE-2008-4143

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2007-6057

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.
0
Attacker Value
Unknown

CVE-2007-5992

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page.
0
Attacker Value
Unknown

CVE-2006-1109

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE.
0
Attacker Value
Unknown

CVE-2006-0374

Disclosure Date: January 22, 2006 (last updated February 22, 2025)
Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).
0