CVE-2013-7317
- EPSS 0.59%
- Veröffentlicht 24.01.2014 15:08:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) settings_file or (2) data_file parameter to (a) ampie.swf, (b) amline.swf, or (c) amcolumn.swf.
- EPSS 0.33%
- Veröffentlicht 24.02.2013 11:48:21
- Zuletzt bearbeitet 11.04.2025 00:51:21
CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
CVE-2009-4891
- EPSS 0.53%
- Veröffentlicht 11.06.2010 14:30:16
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a products.view action.
CVE-2009-2579
- EPSS 0.19%
- Veröffentlicht 05.08.2009 19:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, ...
CVE-2008-6394
- EPSS 0.7%
- Veröffentlicht 04.03.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.
CVE-2008-1458
- EPSS 0.33%
- Veröffentlicht 24.03.2008 18:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in index.php in CS-Cart 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a products search action. NOTE: it was also reported that 1.3.5-SP2 trial edition is also af...
CVE-2007-0230
- EPSS 1.06%
- Veröffentlicht 13.01.2007 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter. NOTE: CVE and third parties dispute this vulnerability because install_dir is defin...
CVE-2006-2863
- EPSS 8.84%
- Veröffentlicht 06.06.2006 20:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.
CVE-2005-4429
- EPSS 0.34%
- Veröffentlicht 21.12.2005 00:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.