CVE-2020-11007
- EPSS 0.85%
- Veröffentlicht 16.04.2020 19:15:26
- Zuletzt bearbeitet 21.11.2024 04:56:34
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the sho...
- EPSS 1.14%
- Veröffentlicht 21.08.2014 23:55:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which makes it easier for remote attackers to guess passwords via a brute force attack.
CVE-2014-4962
- EPSS 4.71%
- Veröffentlicht 15.07.2014 14:55:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.
CVE-2014-4963
- EPSS 3.74%
- Veröffentlicht 15.07.2014 14:55:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.
CVE-2014-4964
- EPSS 2.3%
- Veröffentlicht 15.07.2014 14:55:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users for requests that (1) modify customer settings or hijack the authentication of administrators for re...
CVE-2014-4965
- EPSS 3.25%
- Veröffentlicht 15.07.2014 14:55:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) customername parameter to central/orders/searchcriteria.action; (2) productname, (3) availabil...