Vulnerabilities > Caupo NET

DATE CVE VULNERABILITY TITLE RISK
2008-06-25 CVE-2008-2866 SQL Injection vulnerability in Caupo.Net Cauposhop Classic 1.3
SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to execute arbitrary SQL commands via the saArticle[ID] parameter.
network
low complexity
caupo-net CWE-89
7.5
2007-11-01 CVE-2007-5784 Code Injection vulnerability in Caupo.Net Cauposhop PRO
PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.
network
caupo-net CWE-94
6.8
2002-07-26 CVE-2002-0439 Unspecified vulnerability in Caupo.Net Cauposhop
Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field.
network
low complexity
caupo-net
7.5