Skip to main content

Vendor/product archive

qualiteam / x-cart CVEs

Beta · best-effort

15 CVEs tagged to qualiteam / x-cart2 Critical, 4 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2017-15285

Published Oct 12, 2017

X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check remote file extensions before…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5455

Published Jul 8, 2015

Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to install/.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0951

Published Apr 5, 2015

X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0950

Published Apr 5, 2015

Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1178

Published Jan 26, 2015

Multiple cross-site scripting (XSS) vulnerabilities in cart.php in X-Cart 5.1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) product_id or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2570

Published Aug 15, 2012

Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the symb parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4907

Published Sep 17, 2007

Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter to (1) config.php, (2) prepa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4904

Published Sep 21, 2006

Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2827

Published Jun 5, 2006

SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pat…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-1822

Published Jun 1, 2005

Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1823

Published Jun 1, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0240

Published Nov 23, 2004

Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0241

Published Nov 23, 2004

X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0242

Published Nov 23, 2004

X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1