VYPR

Shop Cart

by Comersus

CVEs (2)

  • CVE-2007-3323Jun 21, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as CVE-2005-2190.2.

  • CVE-2004-1656Sep 1, 2004
    risk 0.03cvss epss 0.06

    CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.