Show filters
136 Total Results
Displaying 91-100 of 136
Sort by:
Attacker Value
Unknown
CVE-2006-6209
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to Item_Show.asp is covered by CVE-2005-2601.
0
Attacker Value
Unknown
CVE-2006-6206
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
SQL injection vulnerability in item.asp in WarHound General Shopping Cart allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
0
Attacker Value
Unknown
CVE-2006-6074
Disclosure Date: November 24, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector is already covered by another identifier.
0
Attacker Value
Unknown
CVE-2006-6073
Disclosure Date: November 24, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.
0
Attacker Value
Unknown
CVE-2006-5962
Disclosure Date: November 17, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
0
Attacker Value
Unknown
CVE-2006-4967
Disclosure Date: September 25, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in NextAge Cart allow remote attackers to inject arbitrary web script or HTML via (1) the CatId parameter in a product category action in index.php or (2) the SearchWd parameter in an index search action in index.php.
0
Attacker Value
Unknown
CVE-2006-3794
Disclosure Date: July 24, 2006 (last updated November 08, 2023)
SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried.
0
Attacker Value
Unknown
CVE-2006-3800
Disclosure Date: July 24, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box.
0
Attacker Value
Unknown
CVE-2006-3542
Disclosure Date: July 13, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown Shopping Cart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) shop name field in (a) editshop.php, (b) edititem.php, and (c) index.php; and via the (2) item field in editshop.php and edititem.php.
0
Attacker Value
Unknown
CVE-2006-3030
Disclosure Date: June 15, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ToCategory and (2) FromCategory parameters to (a) ProductDetailsForm.asp and (3) UserName and (4) Password parameters to (b) LogIn/VerifyUserLog.asp.
0