8 results (0.012 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 3

ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installation path in an error message. Viart Shop (alias Shopping Cart) v3.5 permite a atacantes remotos obtener información sensible a través de una URL en el parámetro POST_DATA a manuals_search.php, el cual revela la ruta de instalación en un mensaje de error. • http://www.osvdb.org/53281 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securityfocus.com/bid/33043 http://www.securitytracker.com/id?1021497 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 3

ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter. Viart Shop (alias Shopping Cart) v3.5 permite a atacantes remotos acceder al contenido de un carrito de la compra a su elección a través de un parámetro cart_name modificado. • https://www.exploit-db.com/exploits/7628 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securityfocus.com/bid/33043 http://www.securitytracker.com/id?1021497 •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 4

Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en cart_save.php en Viart Shop (alias Shopping Cart) v3.5 permite a atacantes remotos secuestrar la autenticación de usuarios a su elección para las solicitudes que conducen ataques persistentes de ejecución de secuencias de comandos en sitios cruzados(XSS) a través del parámetro cart_name en una acción de guardar. • https://www.exploit-db.com/exploits/7628 http://osvdb.org/51029 http://osvdb.org/53283 http://secunia.com/advisories/33340 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securityfocus.com/bid/33043 http://www.securitytracker.com/id?1021497 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of service (excessive shopping carts) via a flood of requests. cart_save.php en Viart Shop (alias Shopping Cart) v3.5 permite a atacantes remotos provocar una denegación de servicio (exceso de carritos de la compra) a través de una avalancha de solicitudes. • http://www.osvdb.org/53285 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securitytracker.com/id?1021497 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 2

ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter. Viart Shop (alias Shopping Cart) v3.5 permite a atacantes remotos obtener información sensible a través de una acción añadir y salvar no autenticada para un carro de compra en cart_save.php, lo cual revela los nombres de tabla de SQL en un mensaje de error, relacionado con el código que pierde el control a falta de un parámetro user_id. • http://www.osvdb.org/53282 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securityfocus.com/bid/33043 http://www.securitytracker.com/id?1021497 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •