Comersus Open Technologies
Comersus Open Technologies Comersus Cart: vulnerabilidades y CVE
Comersus Open Technologies Comersus Cart tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2007-3324 | Media (4.3) | 1.8% | — | 21 jun 2007 | Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter to (1) comersus_customerAuthenticateForm.asp or (2)… |
| CVE-2007-3323 | Alta (7.5) | 1.0% | — | 21 jun 2007 | SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as… |
| CVE-2005-2191 | Media (4.3) | 1.2% | — | 11 jul 2005 | Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to… |
| CVE-2005-2190 | Alta (7.5) | 1.1% | — | 11 jul 2005 | Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct… |
| CVE-2005-1010 | Media (4.3) | 1.2% | — | 2 may 2005 | Cross-site scripting (XSS) vulnerability in Comersus Cart 6 allows remote attackers to inject arbitrary web script or HTML via the account username. |
| CVE-2005-1188 | Media (4.3) | 3.6% | — | 2 may 2005 | Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or HTML via the curPage parameter. |
| CVE-2004-1656 | Media (5) | 2.3% | — | 1 sept 2004 | CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter. |
| CVE-2004-0681 | Media (6.8) | 2.0% | — | 6 ago 2004 | Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in Comersus Cart 5.09… |
| CVE-2004-0682 | Alta (7.5) | 6.9% | — | 6 ago 2004 | comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by directly modifying them in the URL. |