11 results (0.001 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 2

ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter. Viart Shop (alias Shopping Cart) v3.5 permite a atacantes remotos obtener información sensible a través de una acción añadir y salvar no autenticada para un carro de compra en cart_save.php, lo cual revela los nombres de tabla de SQL en un mensaje de error, relacionado con el código que pierde el control a falta de un parámetro user_id. • http://www.osvdb.org/53282 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securityfocus.com/bid/33043 http://www.securitytracker.com/id?1021497 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en manuals_search.php en ViArt Shop (alias Shopping Cart) v3.5 permite a atacantes remotos inyectar HTML o scripts web arbitrarios a través del parámetro manuals_search. • https://www.exploit-db.com/exploits/32685 http://secunia.com/advisories/33340 http://www.osvdb.org/53284 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securityfocus.com/bid/33043 http://www.securitytracker.com/id?1021497 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 4

Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en cart_save.php en Viart Shop (alias Shopping Cart) v3.5 permite a atacantes remotos secuestrar la autenticación de usuarios a su elección para las solicitudes que conducen ataques persistentes de ejecución de secuencias de comandos en sitios cruzados(XSS) a través del parámetro cart_name en una acción de guardar. • https://www.exploit-db.com/exploits/7628 http://osvdb.org/51029 http://osvdb.org/53283 http://secunia.com/advisories/33340 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securityfocus.com/bid/33043 http://www.securitytracker.com/id?1021497 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 3

ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installation path in an error message. Viart Shop (alias Shopping Cart) v3.5 permite a atacantes remotos obtener información sensible a través de una URL en el parámetro POST_DATA a manuals_search.php, el cual revela la ruta de instalación en un mensaje de error. • http://www.osvdb.org/53281 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securityfocus.com/bid/33043 http://www.securitytracker.com/id?1021497 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of service (excessive shopping carts) via a flood of requests. cart_save.php en Viart Shop (alias Shopping Cart) v3.5 permite a atacantes remotos provocar una denegación de servicio (exceso de carritos de la compra) a través de una avalancha de solicitudes. • http://www.osvdb.org/53285 http://www.securityfocus.com/archive/1/499625/100/0/threaded http://www.securitytracker.com/id?1021497 •