Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Amazing Flash Commerce Subscribe
Filtered by product Afcommerce Shopping Cart
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-3794 1 Amazing Flash Commerce 1 Afcommerce Shopping Cart 2018-10-17 7.5 HIGH N/A
** DISPUTED ** SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried."
CVE-2006-3800 1 Amazing Flash Commerce 1 Afcommerce Shopping Cart 2018-10-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box.