Vulnerabilities > Iscripts > Multicart

DATE CVE VULNERABILITY TITLE RISK
2008-02-22 CVE-2008-0911 SQL Injection vulnerability in Iscripts Multicart 2.0
SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.
network
low complexity
iscripts CWE-89
6.5
2007-10-06 CVE-2007-5261 SQL Injection vulnerability in Iscripts Multicart 1.0
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php.
network
low complexity
iscripts CWE-89
6.4