Skip to main content

Vendor/product archive

comdev / comdev_ecommerce CVEs

Beta · best-effort

4 CVEs tagged to comdev / comdev_ecommerce0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2007-3081

Published Jun 6, 2007

PHP remote file inclusion vulnerability in sampleecommerce.php in Comdev eCommerce 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] paramet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2543

Published Aug 10, 2005

Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2544

Published Aug 10, 2005

PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the path[docroot] parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2138

Published Jul 5, 2005

Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseO…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1