VYPR

Nz Ecommerce

by Digital Builder

CVEs (2)

  • CVE-2006-1098Mar 9, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem

  • CVE-2006-1096Mar 9, 2006
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem