Zen-cart

Zen Cart

28 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.66%
  • Published 19.08.2009 05:24:52
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 through 1.3.8a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the products...

Exploit
  • EPSS 2.33%
  • Published 19.08.2009 05:24:52
  • Last modified 09.04.2025 00:30:58

Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2) upd...

Exploit
  • EPSS 31.22%
  • Published 30.06.2009 10:30:19
  • Last modified 09.04.2025 00:30:58

Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the record_company_image parameter in conjunction wi...

Exploit
  • EPSS 9.57%
  • Published 30.06.2009 10:30:11
  • Last modified 09.04.2025 00:30:58

Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute action, in conjunction with a PATH...

Exploit
  • EPSS 0.14%
  • Published 06.04.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in the advanced_search_result page. NOTE: the provenance of this information ...

Exploit
  • EPSS 0.11%
  • Published 06.04.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to execute arbitrary SQL commands via the keyword parameter in the advanced_search_result page. NOTE: the provenance of this information is unknown; the d...

  • EPSS 0.93%
  • Published 15.02.2006 11:06:00
  • Last modified 03.04.2025 01:03:51

Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.

Exploit
  • EPSS 1.73%
  • Published 05.12.2005 00:03:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter.