Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zen Cart MEDIUM 6.8
CVE-2008-6877

Directory traversal vulnerability in admin/includes/initsystem.php in Zen Cart 1.3.8 and 1.3.8a, when .htaccess is not supported, allows remote attac…

No fix yet
Fix from $1,600 2009-07-27
Zen Cart MEDIUM 6.8
CVE-2008-6878

Directory traversal vulnerability in admin/includes/languages/english.php in Zen Cart 1.3.8a, 1.3.8, and earlier, when .htaccess is not supported, al…

No fix yet
Fix from $1,600 2009-07-27
Zen Cart HIGH 8.5
CVE-2007-3597

Session fixation vulnerability in Zen Cart 1.3.7 and earlier allows remote attackers to hijack web sessions by setting the Cookie parameter.

Fix: after 1.3.7
Fix from $1,950 2007-07-06
Web Shopping Cart MEDIUM 6.8
CVE-2006-6868

Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary web script …

Mitigation only
Fix from $1,600 2006-12-31
Zen Cart HIGH 7.5
CVE-2006-4218

Directory traversal vulnerability in Zen Cart 1.3.0.2 and earlier allows remote attackers to include and possibly execute arbitrary local files via d…

Patch available
Fix from $1,950 2006-08-17
Zen Cart HIGH 7.5
CVE-2006-4214

Multiple SQL injection vulnerabilities in Zen Cart 1.3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) GPC data to t…

Fix: after 1.3.0.2
Fix from $1,950 2006-08-17
Zen Cart MEDIUM 5.1
CVE-2006-4215

PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to ex…

Fix: after 1.3.0.2
Fix from $1,600 2006-08-17
Zen Cart MEDIUM 5.0
CVE-2006-3757

index.php in Zen Cart 1.3.0.2 allows remote attackers to obtain sensitive information via empty (1) _GET[], (2) _SESSION[], (3) _POST[], (4) _COOKIE[…

Mitigation only
Fix from $1,600 2006-07-21
Zen Cart HIGH 10.0
CVE-2006-0698

Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempt…

Patch available
Fix from $1,950 2006-02-15
Zen Cart HIGH 7.5
CVE-2006-0696

SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Patch available
Fix from $1,950 2006-02-15
Zen Cart HIGH 7.5
CVE-2004-2023

SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arb…

Patch available
Fix from $1,950 2004-12-31
Zen Cart HIGH 7.5
CVE-2004-2024

The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attacke…

Patch available
Fix from $1,950 2004-12-31
Zen Cart HIGH 7.5
CVE-2004-2025

SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via…

Patch available
Fix from $1,950 2004-12-31