infinicart CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

infinicart vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to infinicart, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2006-5958 Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password fields in (a) login.asp, (3) search field in (b) search.asp, and (4) email field in (c) sendpassword.asp. [email protected] 6.8 2.13% 2006-11-16 2026-06-16
CVE-2006-5957 Multiple SQL injection vulnerabilities in INFINICART allow remote attackers to execute arbitrary SQL commands via the (1) groupid parameter in (a) browse_group.asp, (2) productid parameter in (b) added_to_cart.asp, and (3) catid and (4) subid parameter in (c) browsesubcat.asp. NOTE: the vendor has disputed this report, saying "The vulnerabilities mentioned were never present in our official released products but only in the unofficial demo version. However we do appreciate the information. We h [email protected] 7.5 1.18% 2006-11-16 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence