VendorsMaranphp_shopall versions
Vulnerabilities

Maran PHP Shop

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2008-6296
admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."
Published 2009-02-26 · Modified
7.51 PoCEPSS 0.025
CVE-2008-4880
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.
Published 2008-11-03 · Modified
7.51 PoCEPSS 0.012
CVE-2008-4879
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.
Published 2008-11-03 · Modified
7.51 PoCEPSS 0.010