Required CVE Record Information
Description
Multiple buffer overflows in the (1) vGetPost and (2) main functions in easy-scart.c through easy-scart6.c in iShopCart allow remote attackers to execute arbitrary code by sending a large amount of data containing "Submit" in an sslinvoice action, and allow remote attackers to have an unknown impact via a large amount of posted data.
References 6 Total
- exchange.xforce.ibmcloud.com: ishopcart-easyscart-bo(27014) vdb-entry
- securityfocus.com: 18222 vdb-entry
- securityreason.com: 1031 third-party-advisory
- securityfocus.com: 20060531 ishopcart cgi 0day and multiple vulnerabilities mailing-list
- secunia.com: 20415 third-party-advisory
- vupen.com: ADV-2006-2108 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- exchange.xforce.ibmcloud.com: ishopcart-easyscart-bo(27014) vdb-entryx_transferred
- securityfocus.com: 18222 vdb-entryx_transferred
- securityreason.com: 1031 third-party-advisoryx_transferred
- securityfocus.com: 20060531 ishopcart cgi 0day and multiple vulnerabilities mailing-listx_transferred
- secunia.com: 20415 third-party-advisoryx_transferred
- vupen.com: ADV-2006-2108 vdb-entryx_transferred