Skip to content
Noroxi

cpcommerce records

10 published records for vendor cpcommerce.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
6
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

10 records
  • CVE-2008-1908
    31Monitor

    Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .

    HighCVSS 7.5Proof of conceptEPSS 3%

    cpcommerce · cpcommerceApr 22, 2008

  • CVE-2007-2890
    30Monitor

    SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via th

    HighCVSS 7.5Proof of conceptEPSS 1%

    cpcommerce · cpcommerceMay 29, 2007

  • CVE-2007-2959
    30Monitor

    SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the

    HighCVSS 7.5Proof of conceptEPSS 1%

    cpcommerce · cpcommerceMay 31, 2007

  • CVE-2008-1907
    30Monitor

    Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQ

    HighCVSS 7.5Proof of conceptEPSS 1%

    cpcommerce · cpcommerceApr 22, 2008

  • CVE-2009-1345
    30Monitor

    SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_documen

    HighCVSS 7.5Proof of conceptEPSS 1%

    cpcommerce · cpcommerceApr 20, 2009

  • CVE-2003-1500
    28Monitor

    PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefi

    MediumCVSS 6.8No exploitEPSS 3%

    cpcommerce · cpcommerceDec 31, 2003

  • CVE-2008-1906
    18Monitor

    Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML

    MediumCVSS 4.3Proof of conceptEPSS 2%

    cpcommerce · cpcommerceApr 22, 2008

  • CVE-2008-4121
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML

    MediumCVSS 4.3No exploitEPSS 1%

    cpcommerce · cpcommerceOct 21, 2008

  • CVE-2007-2968
    17Monitor

    Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web scr

    MediumCVSS 4.3No exploitEPSS 1%

    cpcommerce · cpcommerceMay 31, 2007

  • CVE-2008-4637
    17Monitor

    Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unkno

    MediumCVSS 4.3No exploitEPSS 1%

    cpcommerce · cpcommerceOct 21, 2008