Vulnerabilities > ZEN Cart > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-08-17 | CVE-2006-4215 | Code Injection vulnerability in ZEN Cart ZEN Cart PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the autoLoadConfig[999][0][loadFile] parameter. | 5.1 |
2006-07-21 | CVE-2006-3757 | Information Disclosure vulnerability in ZEN Cart ZEN Cart 1.3.0.2 index.php in Zen Cart 1.3.0.2 allows remote attackers to obtain sensitive information via empty (1) _GET[], (2) _SESSION[], (3) _POST[], (4) _COOKIE[], or (5) _SESSION[] array parameters, which reveals the installation path in an error message. | 5.0 |
2005-12-05 | CVE-2005-3996 | SQL Injection vulnerability in Zen-Cart ZEN Cart SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter. | 5.1 |