Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Turnkey Web Tools Subscribe
Filtered by product Sunshop Shopping Cart
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-2474 1 Turnkey Web Tools 1 Sunshop Shopping Cart 2018-10-16 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070.
CVE-2007-2547 1 Turnkey Web Tools 1 Sunshop Shopping Cart 2018-10-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter.
CVE-2007-2548 1 Turnkey Web Tools 1 Sunshop Shopping Cart 2018-10-16 6.4 MEDIUM N/A
Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to "Cookie Manipulation."
CVE-2007-2549 1 Turnkey Web Tools 1 Sunshop Shopping Cart 2018-10-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter.
CVE-2007-2070 1 Turnkey Web Tools 1 Sunshop Shopping Cart 2017-10-10 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.
CVE-2007-4597 1 Turnkey Web Tools 1 Sunshop Shopping Cart 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549.