Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
virtuemart virtuemart vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2005-4829
VirtueMart prior to 1.0.1 does not properly handle errors when a user is forbidden to read a requested page, which has unknown impact and remote attack vectors.
Virtuemart Virtuemart
7.5
CVSSv2
CVE-2016-10114
SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension prior to 2.6.1 for Joomla! allows remote malicious users to execute arbitrary SQL commands via vectors involving categorysearch and smartSearch.
Awebsupport Aweb Cart Watching System For Virtuemart 2.6.0
7.5
CVSSv2
CVE-2009-4430
SQL injection vulnerability in index.php in VirtueMart 1.0 allows remote malicious users to execute arbitrary SQL commands via the product_id parameter in a shop.product_details shop.flypage action.
Virtuemart Virtuemart 1.0
1 EDB exploit
7.5
CVSSv2
CVE-2008-6483
PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) component 1.1 for Joomla! allows remote malicious users to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Virtuemart-solutions Com Googlebase 1.1
1 EDB exploit
7.5
CVSSv2
CVE-2007-5563
Unspecified vulnerability in VirtueMart prior to 1.0.13 allows remote malicious users to execute arbitrary PHP code via unspecified vectors.
Virtuemart Virtuemart
7.5
CVSSv2
CVE-2006-6945
SQL injection vulnerability in Virtuemart 1.0.7 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors, probably related to (1) Itemid, (2) product_id, and category_id parameters as handled in virtuemart_parser.php.
Virtuemart Virtuemart 1.0.7
6.8
CVSSv2
CVE-2008-7204
Cross-site request forgery (CSRF) vulnerability in VirtueMart 1.0.13a and previous versions allows remote malicious users to hijack the authentication of administrators via unspecified vectors.
Virtuemart Virtuemart 1.1
Virtuemart Virtuemart 1.0.0
Virtuemart Virtuemart 1.0.10
Virtuemart Virtuemart 1.0.7
Virtuemart Virtuemart 1.0.12
Virtuemart Virtuemart 1.0.8
Virtuemart Virtuemart 1.0.11
Virtuemart Virtuemart 1.0.9
Virtuemart Virtuemart
6.8
CVSSv2
CVE-2007-3247
SQL injection vulnerability in VirtueMart prior to 1.0.11 allows remote malicious users to execute arbitrary SQL commands via unspecified parameters, possibly related to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php.
Virtuemart Virtuemart
6.8
CVSSv2
CVE-2007-1096
Cross-site scripting (XSS) vulnerability in ps_cart.php in VirtueMart prior to 20070116 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue might overlap CVE-2007-0376.
Virtuemart Virtuemart
6.8
CVSSv2
CVE-2007-0376
Cross-site scripting (XSS) vulnerability in Virtuemart 1.0.7 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Virtuemart Virtuemart 1.0.7
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37884
CVE-2024-6003
remote
brute force
information disclosure
CVE-2024-27801
CVE-2024-30078
CVE-2024-31870
CVE-2024-6042
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »