VYPR

Ckgold Shopping Cart

by Cartkeeper

CVEs (3)

  • CVE-2008-2774Jun 19, 2008
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execute arbitrary SQL commands via the category_id parameter, a different vector than CVE-2007-4736.

  • CVE-2007-4736Sep 6, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

  • CVE-2005-4236Dec 14, 2005
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in search.php in CKGOLD allows remote attackers to inject arbitrary web script or HTML via the search parameters.