Vulnerabilities (CVE)

Filtered by vendor Ishopcart Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-2813 1 Ishopcart 1 Ishopcart 2024-02-04 7.8 HIGH N/A
Directory traversal vulnerability in easy-scart.cgi in iShopCart allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.
CVE-2006-2814 1 Ishopcart 1 Ishopcart 2024-02-04 7.5 HIGH N/A
Multiple buffer overflows in the (1) vGetPost and (2) main functions in easy-scart.c through easy-scart6.c in iShopCart allow remote attackers to execute arbitrary code by sending a large amount of data containing "Submit" in an sslinvoice action, and allow remote attackers to have an unknown impact via a large amount of posted data.