Skip to main content

Vendor/product archive

shoppingtree / candypress_store CVEs

Beta · best-effort

6 CVEs tagged to shoppingtree / candypress_store0 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2008-0736

Published Feb 13, 2008

admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccoun…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0737

Published Feb 13, 2008

SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL command…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0738

Published Feb 13, 2008

Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust paramet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0739

Published Feb 13, 2008

SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0546

Published Feb 1, 2008

Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0547

Published Feb 1, 2008

Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to injec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1