VendorsAJ Squarezeuscart4.0
Vulnerabilities

AJ Square Zeuscart 4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-2184
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.
Published 2015-03-10 · Modified
5.01 PoCEPSS 0.084
CVE-2015-2182
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) schltr parameter in a brands action or (2) brand parameter in a viewbrands action to index.php. NOTE: The search parameter vector is already covered by CVE-2010-5322.
Published 2015-03-11 · Modified
4.31 PoCEPSS 0.045