Show filters
136 Total Results
Displaying 91-100 of 136
Sort by:
Attacker Value
Unknown

CVE-2006-6209

Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to Item_Show.asp is covered by CVE-2005-2601.
0
Attacker Value
Unknown

CVE-2006-6206

Disclosure Date: December 01, 2006 (last updated October 04, 2023)
SQL injection vulnerability in item.asp in WarHound General Shopping Cart allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
0
Attacker Value
Unknown

CVE-2006-6074

Disclosure Date: November 24, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector is already covered by another identifier.
0
Attacker Value
Unknown

CVE-2006-6073

Disclosure Date: November 24, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.
0
Attacker Value
Unknown

CVE-2006-5962

Disclosure Date: November 17, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
0
Attacker Value
Unknown

CVE-2006-4967

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in NextAge Cart allow remote attackers to inject arbitrary web script or HTML via (1) the CatId parameter in a product category action in index.php or (2) the SearchWd parameter in an index search action in index.php.
0
Attacker Value
Unknown

CVE-2006-3794

Disclosure Date: July 24, 2006 (last updated November 08, 2023)
SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried.
0
Attacker Value
Unknown

CVE-2006-3800

Disclosure Date: July 24, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box.
0
Attacker Value
Unknown

CVE-2006-3542

Disclosure Date: July 13, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown Shopping Cart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) shop name field in (a) editshop.php, (b) edititem.php, and (c) index.php; and via the (2) item field in editshop.php and edititem.php.
0
Attacker Value
Unknown

CVE-2006-3030

Disclosure Date: June 15, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ToCategory and (2) FromCategory parameters to (a) ProductDetailsForm.asp and (3) UserName and (4) Password parameters to (b) LogIn/VerifyUserLog.asp.
0