This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Cs-Cart First view 2013-02-24
Product Cs-Cart Last view 2017-11-28
Version 2.0.11 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:cs-cart:cs-cart

Activity : Overall

Related : CVE

  Date Alert Description
7.2 2017-11-28 CVE-2017-15673

The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page.

8.8 2017-08-02 CVE-2017-2138

Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

8.8 2017-04-20 CVE-2016-4862

Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.

4.3 2014-01-24 CVE-2013-7317

Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) settings_file or (2) data_file parameter to (a) ampie.swf, (b) amline.swf, or (c) amcolumn.swf.

5 2013-02-24 CVE-2013-0118

CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.

CWE : Common Weakness Enumeration

%idName
20% (1) CWE-434 Unrestricted Upload of File with Dangerous Type
20% (1) CWE-352 Cross-Site Request Forgery (CSRF)
20% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
20% (1) CWE-20 Improper Input Validation
20% (1) CWE-16 Configuration

Nessus® Vulnerability Scanner

id Description
2015-04-10 Name: The remote host is missing a Mac OS X update that fixes multiple security vul...
File: macosx_10_10_3.nasl - Type: ACT_GATHER_INFO
2015-04-10 Name: The remote host is missing a Mac OS X update that fixes multiple security vul...
File: macosx_SecUpd2015-004.nasl - Type: ACT_GATHER_INFO