Vulnerabilities > Kryptronic

DATE CVE VULNERABILITY TITLE RISK
2005-12-16 CVE-2005-4293 Cross-Site Scripting vulnerability in Kryptronic ClickCartPro CP-APP.CGI
Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.
network
kryptronic
4.3
2002-12-31 CVE-2002-2310 Credentials Management vulnerability in Kryptronic Clickcartpro 4.0
ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
network
low complexity
kryptronic CWE-255
5.0