VendorsEcommerce Corporation Onlinestore_kitall versions
Vulnerabilities

Ecommerce Corporation Online Store Kit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2004-0300
SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.
Published 2004-03-18 · Modified
10.04 PoCEPSS 0.052
CVE-2004-0301
Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.
Published 2004-03-18 · Modified
6.81 PoCEPSS 0.042