CVE Tools

Comersus-open-technologies

14 CVEs tracked since 2004. Since Jul 2004, none of them reached CISA KEV.

Comersus-open-technologies CVEs per month

Jul 2004 to Jun 2007. Point at a month, or focus the strip and use the arrow keys.
Comersus-open-technologies CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2004-0720
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-0240
2005-03null or fewer
2005-0420
2005-05null or fewer
2005-06null or fewer
2005-0720
2005-08null or fewer
2005-09null or fewer
2005-1010
2005-1110
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-0620

Products

The products that kept showing up in Comersus-open-technologies's monthly top three, with their CVEs summed over those months.

  1. Comersus Cart95 months
  2. Comersus Backoffice Lite42 months
  3. Comersus Backoffice Plus22 months

Latest CVEs

The 14 most recently published vulnerabilities affecting Comersus-open-technologies.

  1. CVE-2007-3324Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter to (1) comersus_customerAuthent...4.3
  2. CVE-2007-3323SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be ...7.5
  3. CVE-2005-3397Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE...4.3
  4. CVE-2005-3285Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1,...4.3
  5. CVE-2005-2191Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAss...4.3
  6. CVE-2005-2190Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or...7.5
  7. CVE-2005-1188Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or HTML via the curPage parameter.4.3
  8. CVE-2005-1010Cross-site scripting (XSS) vulnerability in Comersus Cart 6 allows remote attackers to inject arbitrary web script or HTML via the account username.4.3
  9. CVE-2004-1656CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl ...5.0
  10. CVE-2005-0302SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header.7.5
  11. CVE-2005-0301comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.7.5
  12. CVE-2005-0303Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject...4.3
  13. CVE-2004-0682comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by directly modifying them in the URL.7.5
  14. CVE-2004-0681Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in ...6.8

The record

Peak rank
#20 in Jul 2004
Busiest month shown
Feb 2005, 4 CVEs
Months with a KEV entry
0 since Jul 2004
Monthly snapshots
7 since 2004
Comersus-open-technologies's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store