Vulnerabilities > Reality66 > Cart66 Lite > 1.5.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2015-01-02 | CVE-2014-9461 | Path Traversal vulnerability in Reality66 Cart66 Lite 1.5.1.17/1.5.3 Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to read arbitrary files via a .. | 3.5 |
2015-01-02 | CVE-2014-9442 | SQL Injection vulnerability in Reality66 Cart66 Lite 1.5.3 SQL injection vulnerability in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the q parameter in a promotionProductSearch action to wp-admin/admin-ajax.php. | 6.5 |