Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2012-1413

Disclosure Date: May 27, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.
0
Attacker Value
Unknown

CVE-2011-4567

Disclosure Date: November 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.php, a different vulnerability than CVE-2011-4547.
0
Attacker Value
Unknown

CVE-2009-2255

Disclosure Date: June 30, 2009 (last updated October 04, 2023)
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the record_company_image parameter in conjunction with a PATH_INFO of password_forgotten.php, then accessing this file via a direct request to the file in images/.
0
Attacker Value
Unknown

CVE-2009-2254

Disclosure Date: June 30, 2009 (last updated October 04, 2023)
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute action, in conjunction with a PATH_INFO of password_forgotten.php, related to a "SQL Execution" issue.
0
Attacker Value
Unknown

CVE-2006-0697

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
0
Attacker Value
Unknown

CVE-2006-0698

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.
0
Attacker Value
Unknown

CVE-2006-0696

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0