Vulnerabilities > ZEN Cart > Medium

DATE CVE VULNERABILITY TITLE RISK
2006-08-17 CVE-2006-4215 Code Injection vulnerability in ZEN Cart ZEN Cart
PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the autoLoadConfig[999][0][loadFile] parameter.
network
high complexity
zen-cart CWE-94
5.1
2006-07-21 CVE-2006-3757 Information Disclosure vulnerability in ZEN Cart ZEN Cart 1.3.0.2
index.php in Zen Cart 1.3.0.2 allows remote attackers to obtain sensitive information via empty (1) _GET[], (2) _SESSION[], (3) _POST[], (4) _COOKIE[], or (5) _SESSION[] array parameters, which reveals the installation path in an error message.
network
low complexity
zen-cart
5.0
2005-12-05 CVE-2005-3996 SQL Injection vulnerability in Zen-Cart ZEN Cart
SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter.
network
high complexity
zen-cart CWE-89
5.1