VYPR

PHP Shop

by Maran

CVEs (3)

  • CVE-2008-6296Feb 26, 2009
    risk 0.03cvss epss 0.02

    admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."

  • CVE-2008-4880Nov 4, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.

  • CVE-2008-4879Nov 4, 2008
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.