Skip to main content

Vendor/product archive

cactusoft / cactushop CVEs

Beta · best-effort

4 CVEs tagged to cactusoft / cactushop0 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2007-3061

Published Jun 6, 2007

Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5991

Published Nov 21, 2006

Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prodtype parameter in prodtype.asp and the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1881

Published Dec 31, 2004

SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1882

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1