NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49506 | CVE-2009-2254 | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute action, in conjunction with a PATH_INFO of password_forgotten.php, related to a "SQL Execution" issue. | 2 | 7.5 | High | 2017-01-07 | 2009-06-30 | View | |
86087 | CVE-2017-8833 | Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of Download latest in-development version from github. | 2 | 4.3 | Medium | 2017-06-03 | 2017-05-30 | View | |
59428 | CVE-2006-0697 | Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests. | 2 | 10 | High | 2016-12-20 | 2013-01-03 | View | |
55300 | CVE-2007-3146 | Zen Help Desk 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for ZenHelpDesk.mdb. | 2 | 5 | Medium | 2017-01-07 | 2012-10-30 | View | |
10929 | CVE-2011-4533 | zenAdminSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted packet to TCP port 50777, aka Reference Number 25240. | 2 | 7.5 | High | 2017-01-07 | 2012-02-13 | View |
Page 17640 of 17672, showing 5 records out of 88360 total, starting on record 88196, ending on 88200