Lucene search

K

Turnkey Web Tools Security Vulnerabilities

cve
cve

CVE-2005-4787

Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in...

6.8AI Score

0.003EPSS

2022-10-03 04:22 PM
23
cve
cve

CVE-2008-2038

Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) orderby and (2) sort parameters. NOTE: the provenance of this information is unknown; the details.....

7.8AI Score

0.002EPSS

2008-04-30 04:17 PM
20
cve
cve

CVE-2007-4597

SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than...

8.2AI Score

0.008EPSS

2007-08-30 06:17 PM
16
cve
cve

CVE-2007-2549

SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity...

8.2AI Score

0.008EPSS

2007-05-09 10:19 AM
20
cve
cve

CVE-2007-2547

Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l...

5.7AI Score

0.008EPSS

2007-05-09 10:19 AM
19
cve
cve

CVE-2007-2548

Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to "Cookie...

6.7AI Score

0.005EPSS

2007-05-09 10:19 AM
21
cve
cve

CVE-2007-2474

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than...

7.5AI Score

0.113EPSS

2007-05-02 11:19 PM
17
cve
cve

CVE-2007-2070

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2)...

7.5AI Score

0.113EPSS

2007-04-18 03:19 AM
23
cve
cve

CVE-2006-4052

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) admin/index.php, (2) admin/adminindex.php, (3) admin/adminglobal.php, (4) admin/login.php, (5)...

7.7AI Score

0.681EPSS

2006-08-10 12:04 AM
97
cve
cve

CVE-2006-4051

PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path...

7.5AI Score

0.056EPSS

2006-08-10 12:04 AM
93
cve
cve

CVE-2006-2394

Cross-site scripting (XSS) vulnerability in chat.php in PHP Live Helper allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID...

5.8AI Score

0.004EPSS

2006-05-16 01:02 AM
22
cve
cve

CVE-2006-1478

Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie,...

6.9AI Score

0.01EPSS

2006-03-29 01:06 AM
20
cve
cve

CVE-2006-1477

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php,....

7.6AI Score

0.345EPSS

2006-03-29 01:06 AM
26