CVE Browser
CVE-2005-1595 MEDIUM
CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.
CVSS 5.0 EPSS 1.80% May 16, 2005
CVE-2005-1594 HIGH
SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVSS 7.5 EPSS 1.40% May 16, 2005
CVE-2005-1593 MEDIUM
Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the…
CVSS 6.8 EPSS 4.23% May 16, 2005
Showing 1 to 3 CVEs · page 1