Vulnerabilities
Vulnerable Software
Opencart:  >> Opencart  >> 1.5.5.1  Security Vulnerabilities
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP object, related to the quantity parameter in an update request.
CVSS Score
9.8
EPSS Score
0.11
Published
2018-03-20
Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id parameter to index.php.
CVSS Score
6.1
EPSS Score
0.003
Published
2016-01-12


Contact Us

Shodan ® - All rights reserved