Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Salescart Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0102 1 Salescart 1 Salescart 2022-08-17 7.5 HIGH N/A
The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2007-2997 1 Salescart 1 Shopping Cart 2018-10-16 7.5 HIGH N/A
** DISPUTED ** Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo on the website but not on the released product."