Zen-cart
Zen-cart ZEN Cart: vulnerabilidades y CVE
Zen-cart ZEN Cart tiene 27 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-5762 | Alta (8.1) | 72% | — | 21 ago 2024 | Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not… |
| CVE-2020-6578 | Media (6.1) | 0.84% | — | 19 mar 2021 | Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php. |
| CVE-2021-3291 | Alta (7.2) | 17% | — | 26 ene 2021 | Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command. |
| CVE-2015-8352 | Crítica (9.8) | 16% | — | 24 ago 2017 | Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php. |
| CVE-2017-11675 | Alta (8.8) | 2.9% | — | 27 jul 2017 | The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP code by placing that… |
| CVE-2017-10667 | Media (6.1) | 0.65% | — | 29 jun 2017 | In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS. |
| CVE-2017-8833 | Media (6.1) | 0.68% | — | 8 may 2017 | Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development… |
| CVE-2011-4403 | Media (5.8) | 1.7% | — | 24 abr 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm… |
| CVE-2015-0882 | Media (4.3) | 2.2% | — | 27 feb 2015 | Multiple cross-site scripting (XSS) vulnerabilities in zencart-ja (aka Zen Cart Japanese edition) 1.3 jp through 1.3.0.2 jp8 and 1.5 ja through 1.5.1 ja allow remote attackers to inject arbitrary web script or HTML via… |
| CVE-2012-5808 | Media (5.8) | 0.57% | — | 4 nov 2012 | The LinkPoint module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle… |
| CVE-2012-5807 | Media (5.8) | 0.57% | — | 4 nov 2012 | The Authorize.Net eCheck module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows… |
| CVE-2012-5806 | Media (5.8) | 0.57% | — | 4 nov 2012 | The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows… |
| CVE-2012-5805 | Media (5.8) | 0.57% | — | 4 nov 2012 | The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle… |
| CVE-2012-1413 | Baja (2.6) | 0.84% | — | 27 may 2012 | Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject… |
| CVE-2011-4567 | Media (4.3) | 1.5% | — | 29 nov 2011 | Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message… |
| CVE-2011-4547 | Media (4.3) | 1.1% | — | 29 nov 2011 | Multiple cross-site scripting (XSS) vulnerabilities in includes/templates/template_default/common/tpl_header_test_info.php in Zen Cart 1.3.9h, when debugging is enabled, might allow remote attackers to inject arbitrary… |
| CVE-2009-4323 | Alta (7.5) | 2.6% | — | 14 dic 2009 | The installation for Zen Cart stores sensitive information and insecure programs under the (1) docs, (2) extras, and (3) zc_install folders, and (4) install.txt, which allows remote attackers to obtain sensitive… |
| CVE-2009-4322 | Media (5) | 1.3% | — | 14 dic 2009 | extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. |
| CVE-2009-4321 | Media (5) | 2.5% | — | 14 dic 2009 | extras/curltest.php in Zen Cart 1.3.8 and 1.3.8a, and possibly other versions, allows remote attackers to read arbitrary files via a file:// URI. NOTE: some of these details are obtained from third party information. |
| CVE-2008-6986 | Media (6.8) | 2.8% | — | 19 ago 2009 | SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 through 1.3.8a, when magic_quotes_gpc is disabled, allows remote attackers to execute… |
| CVE-2008-6985 | Media (6.8) | 1.6% | — | 19 ago 2009 | Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id… |
| CVE-2009-2255 | Media (6.8) | 31% | — | 30 jun 2009 | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the… |
| CVE-2009-2254 | Alta (7.5) | 11% | — | 30 jun 2009 | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute… |
| CVE-2008-6616 | Media (4.3) | 1.4% | — | 6 abr 2009 | Cross-site scripting (XSS) vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in the advanced_search_result page. NOTE: the… |
| CVE-2008-6615 | Alta (7.5) | 0.96% | — | 6 abr 2009 | SQL injection vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to execute arbitrary SQL commands via the keyword parameter in the advanced_search_result page. NOTE: the provenance of this… |
| CVE-2006-0697 | Alta (10) | 5.2% | — | 15 feb 2006 | Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests. |
| CVE-2005-3996 | Media (5.1) | 1.9% | — | 5 dic 2005 | SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter. |