Vulnerabilities
Vulnerable Software
Phpcart:  >> Phpcart  >> 3.4  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Carmosa phpCart 3.4 through 4.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) quantity or (2) Add Engraving fields to the default URI; (3) Quantity field to phpcart.php; (4) Name, (5) Company, (6) Address, (7) City, and (8) Province/State fields in a checkout action to phpcart.php; and other unspecified vectors.
CVSS Score
4.3
EPSS Score
0.003
Published
2009-08-28
phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 through 4.6.4 are also affected.
CVSS Score
5.0
EPSS Score
0.113
Published
2005-05-03


Contact Us

Shodan ® - All rights reserved