VendorsNaxtorshopping_cartall versions
Vulnerabilities

Naxtor Shopping Cart

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2005-2477
shop_display_products.php in Naxtor Shopping Cart 1.0 allows remote attackers to obtain sensitive information via a cat_id with a "'" (single quote), which reveals the path in an error message, possibly due to an SQL injection vulnerability.
Published 2005-08-05 · Modified
5.0EPSS 0.012
CVE-2005-2476
Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
Published 2005-08-05 · Modified
4.31 PoCEPSS 0.017