Mcmurtrey Whitaker And Associates

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2007-5253

    c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00) sequence followed by an image file extension, as demonstrated by a request for a ".txt%00.gif" file. NOTE: this might be a directory traversal vulnerability.

    Last Modified: Apr 23, 2026
    Published: Oct 06, 2007

    CVE-2004-0675

    Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command.

    Last Modified: Apr 16, 2026
    Published: Jul 13, 2004

    CVE-2000-0430

    Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.

    Last Modified: Apr 16, 2026
    Published: May 03, 2000

    CVE-2000-0429

    A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.

    Last Modified: Apr 16, 2026
    Published: Apr 27, 2000

    CVE-2000-0136

    The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

    Last Modified: Apr 16, 2026
    Published: Feb 01, 2000
    Items Per Page
    Mcmurtrey_Whitaker_And_Associates Vulnerabilities & Security… | CVE-DB