NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 43911 | CVE-2012-2058 | The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2012-09-19 | View | |
| 35847 | CVE-2014-9026 | The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2014-11-20 | View | |
| 44116 | CVE-2012-2301 | The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors. | 2 | 6 | Medium | 2017-01-19 | 2014-11-19 | View | |
| 44114 | CVE-2012-2299 | The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal stores passwords for new customers in plaintext during checkout, which allows local users to obtain sensitive information by reading from the database. | 2 | 2.1 | Low | 2017-01-19 | 2012-08-15 | View | |
| 44446 | CVE-2012-2731 | The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage. | 2 | 2.6 | Low | 2017-01-19 | 2012-06-27 | View |
Page 2869 of 17672, showing 5 records out of 88360 total, starting on record 14341, ending on 14345