Skip to main content

Vendor archive

cactusoft CVEs

Beta · best-effort

8 CVEs tagged to vendor cactusoft0 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2007-3061

Published Jun 6, 2007

Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2818

Published May 22, 2007

Cross-site scripting (XSS) vulnerability in cand_login.asp in CactuSoft Parodia 6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the strJobIDs pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5991

Published Nov 21, 2006

Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prodtype parameter in prodtype.asp and the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1004

Published Mar 6, 2006

Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the AG_ID parameter. N…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1005

Published Mar 6, 2006

agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an invalid AG_ID parameter. NOTE: the pro…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1881

Published Dec 31, 2004

SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1882

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0260

Published Nov 23, 2004

The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1