
2015 Dec 02
appRain 4.0.3: CSRF
None of the forms of appRain 4.0.3 have CSRF protection.
None of the forms of appRain 4.0.3 have CSRF protection.
appRain 4.0.3, Code Execution, vulnerability, advisory
There is an SQL Injection vulnerability in the admin area of AlegroCart 1.2.8.
There is an LFI/RFI vulnerability in the admin area of AlegroCart 1.2.8.
There are multiple XSS vulnerabilities in LiteCart 1.3.2.
There are multiple XSS vulnerabilities in ClipperCMS 1.3.0.
There are multiple SQL Injection vulnerabilities in ClipperCMS 1.3.0.
There is a Path Traversal vulnerability in ClipperCMS 1.3.0
ClipperCMS 1.3.0 has as only CSRF protection a referer check, which can be disabled by an admin.