Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Breakingtech

#19898of 53,608
13Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-7663
6.5
2020-01-31
Zeuscart · Zeuscart · CVE-2014-3868
**Name of the Vulnerable Software and Affected Versions** ZeusCart versions 4.x **Description** The issue involves multiple SQL injection vulnerabilities. **Recommendations** For ZeusCart versions 4.x, update to a version that includes a fix for these SQL injection vulnerabilities.
PT-2020-7709
6.5
2020-01-03
Unknown · Loaded Commerce · CVE-2014-5140
**Name of the Vulnerable Software and Affected Versions** Loaded Commerce version 7 **Description** The issue concerns the bindReplace function in the query factory, which fails to properly handle colon characters. This allows remote authenticated users to conduct SQL injection attacks through the First name and Last name fields in the address book. **Recommendations** For Loaded Commerce version 7, consider restricting access to the address book fields until a proper fix is applied, and ensure that user input is thoroughly sanitized to prevent SQL injection attacks. As a temporary workaround, consider disabling the bindReplace function in the query factory until a patch is available.