VYPR

Tomatocart

by Tomatocart

CVEs (5)

  • CVE-2012-5907Nov 17, 2012
    risk 0.04cvss epss 0.11

    Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter in a "3" action.

  • CVE-2014-3978Oct 20, 2014
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Name fields in a new address book contact.

  • CVE-2014-3830Oct 20, 2014
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in info.php in TomatoCart 1.1.8.6.1 allows remote attackers to inject arbitrary web script or HTML via the faqs_id parameter.

  • CVE-2012-4934Oct 31, 2012
    risk 0.00cvss epss 0.00

    TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL.

  • CVE-2011-3811Sep 24, 2011
    risk 0.00cvss epss 0.00

    TomatoCart 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/system/offline.php and certain other files.