VYPR
Vendor

Salescart

Products
2
CVEs
2
Across products
2
Status
Private

Products

2

Recent CVEs

2
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2007-29970.000.01Jun 4, 2007Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo on the website but not on the released product.
CVE-2000-01020.000.01Feb 1, 2000The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.