Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2008-6765
Disclosure Date: April 28, 2009 (last updated October 04, 2023)
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter.
0
Attacker Value
Unknown
CVE-2008-6759
Disclosure Date: April 28, 2009 (last updated October 04, 2023)
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2008-6757
Disclosure Date: April 28, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter.
0
Attacker Value
Unknown
CVE-2008-6766
Disclosure Date: April 28, 2009 (last updated October 04, 2023)
cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of service (excessive shopping carts) via a flood of requests.
0
Attacker Value
Unknown
CVE-2008-6760
Disclosure Date: April 28, 2009 (last updated October 04, 2023)
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter.
0
Attacker Value
Unknown
CVE-2008-6758
Disclosure Date: April 28, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.
0
Attacker Value
Unknown
CVE-2008-3369
Disclosure Date: July 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
0
Attacker Value
Unknown
CVE-2006-2980
Disclosure Date: June 12, 2006 (last updated October 04, 2023)
SQL injection vulnerability in block_forum_topic_new.php in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, might allow remote attackers to execute arbitrary SQL commands via unknown vectors, probably involving the forum_id parameter.
0
Attacker Value
Unknown
CVE-2005-1440
Disclosure Date: May 03, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.
0