← Back

Multicart

multicart

Vendor: Iscripts • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Iscripts
1Multicart
Apr 23, 2026
Feb 22, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.
1Iscripts
1Multicart
Apr 23, 2026
Oct 6, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php.