VYPR

Multicart

by Iscripts

CVEs (2)

  • CVE-2008-0911Feb 22, 2008
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.

  • CVE-2007-5261Oct 6, 2007
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php.