Vulnerabilities
Cart66 Lite WordPress Ecommerce 1.5.1.17 Blind SQL Injection
`Cart66Ajax
01-12-2014
1 MIN READ
Vulnerabilities
`Cart66Ajax
1 MIN READ
Vulnerabilities
$_POST['text'] is not escaped.
2 MIN READ
Vulnerabilities
Anyone can change plugin settings.
1 MIN READ
Vulnerabilities
Datas are not escaped correctly.
1 MIN READ
Vulnerabilities
$_GET['delete'] is not escaped.
1 MIN READ
Vulnerabilities
json_return() function doesn't check admin privileges.
1 MIN READ
Vulnerabilities
is_admin() function is used to check priveleges but because this code is run in context of wp-admin/admin-ajax.php this function always evalute to true.
1 MIN READ
Vulnerabilities
Datas from Open End questions are not escaped properly.
1 MIN READ
From 0 to pentesting hero
Can you expand the potential attack vector for a larger number of applications?
03-04-2019
3 MIN READ