cbcvebase.

Viart Shop vulnerabilities

7 known vulnerabilities affecting viart/viart_shop.

Total CVEs
7
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2008-3369P3HIGHCVSS 7.5PoC≤ 3.5v2.5.5+3 more2008-07-30
CVE-2008-3369 [HIGH] CWE-89 CVE-2008-3369: SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attacker SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
nvd
CVE-2008-6765P4MEDIUMCVSS 5.0PoCv3.52009-04-28
CVE-2008-6765 [MEDIUM] CVE-2008-6765: ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary sh ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter.
nvd
CVE-2008-6758P4MEDIUMCVSS 6.8PoCv3.52009-04-28
CVE-2008-6758 [MEDIUM] CWE-352 CVE-2008-6758: Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3 Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.
nvd
CVE-2008-6757P4MEDIUMCVSS 4.3PoCv3.52009-04-28
CVE-2008-6757 [MEDIUM] CWE-79 CVE-2008-6757: Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter.
nvd
CVE-2008-6766P4MEDIUMCVSS 5.0v3.52009-04-28
CVE-2008-6766 [MEDIUM] CVE-2008-6766: cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of ser cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of service (excessive shopping carts) via a flood of requests.
nvd
CVE-2008-6760P4MEDIUMCVSS 4.3v3.52009-04-28
CVE-2008-6760 [MEDIUM] CWE-59 CVE-2008-6760: ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an un ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter.
nvd
CVE-2008-6759P4MEDIUMCVSS 4.3v3.52009-04-28
CVE-2008-6759 [MEDIUM] CWE-59 CVE-2008-6759: ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installation path in an error message.
nvd
Viart Shop vulnerabilities | cvebase