VYPR

Squirrelcart

by Lighthouse Development

CVEs (3)

  • CVE-2006-2483May 19, 2006
    risk 0.04cvss epss 0.11

    PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter.

  • CVE-2007-4439Aug 21, 2007
    risk 0.03cvss epss 0.05

    PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_isp_root parameter, probably related to cart.php.

  • CVE-2005-0962May 2, 2005
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.