Vulnerabilities (CVE)

Filtered by vendor Maran Subscribe
Filtered by product Php Shop
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4879 1 Maran 1 Php Shop 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.
CVE-2008-4880 1 Maran 1 Php Shop 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.
CVE-2008-6296 1 Maran 1 Php Shop 2024-02-28 7.5 HIGH N/A
admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."