Page 2 of 7 results (0.002 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to inject arbitrary web script or HTML via (1) unspecified vectors related to purchase_limit or the (2) name, (3) intl, (4) nocod, or (5) time parameter in an add_delivery_method action to wp-admin/admin-ajax.php. Múltiples vulnerabilidades de XSS en el plugin Welcart e-Commerce 1.3.12 para WordPress permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de (1) vectores no especificados relacionados con purchase_limit o del parámetro (2) name, (3) intl, (4) nocod, o (5) time en una acción add_delivery_method en wp-admin/admin-ajax.php. • http://packetstormsecurity.com/files/125513 http://secunia.com/advisories/57222 http://www.securityfocus.com/bid/65954 https://exchange.xforce.ibmcloud.com/vulnerabilities/91541 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 2%CPEs: 1EXPL: 1

Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL. • https://www.exploit-db.com/exploits/20850 http://marc.info/?l=bugtraq&m=98991352402073&w=2 https://exchange.xforce.ibmcloud.com/vulnerabilities/6532 •