Vulnerabilities
Vulnerable Software
Cs-Cart:  >> Cs-Cart  >> 1.2  Security Vulnerabilities
SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2.
CVSS Score
6.5
EPSS Score
0.004
Published
2009-08-05
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.
CVSS Score
7.5
EPSS Score
0.004
Published
2009-03-04


Contact Us

Shodan ® - All rights reserved