Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2012-1413
Disclosure Date: May 27, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.
0
Attacker Value
Unknown
CVE-2011-4567
Disclosure Date: November 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.php, a different vulnerability than CVE-2011-4547.
0
Attacker Value
Unknown
CVE-2009-2255
Disclosure Date: June 30, 2009 (last updated October 04, 2023)
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the record_company_image parameter in conjunction with a PATH_INFO of password_forgotten.php, then accessing this file via a direct request to the file in images/.
0
Attacker Value
Unknown
CVE-2009-2254
Disclosure Date: June 30, 2009 (last updated October 04, 2023)
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute action, in conjunction with a PATH_INFO of password_forgotten.php, related to a "SQL Execution" issue.
0
Attacker Value
Unknown
CVE-2006-0697
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
0
Attacker Value
Unknown
CVE-2006-0698
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.
0
Attacker Value
Unknown
CVE-2006-0696
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2004-2025
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.
0