Metalinks develops a focused suite of e-commerce and auction-platform products, including MetaCart and MetaBid, that serve as storefronts and transaction engines for small to medium business deployments. The vendor's disclosure history concentrates around input-handling and application-layer weaknesses characteristic of web-based commerce systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Metalinks over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1361HIGH Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCata | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1362HIGH Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCa | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1363HIGH Multiple SQL injection vulnerabilities in MetaCart 2.0 for PayFlow allow remote attackers to execute arbitrary commands via (1) intCatalogID, (2) strSubCatalogID, or (3) strSubCata | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1364HIGH Multiple SQL injection vulnerabilities in MetaBid Auctions allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password fields in logIn.asp, or (3) | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2002-0943MEDIUM MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and cred | Oct 4, 2002 | 6.4 | 19 | NO | NO |
CVE-2008-6051MEDIUM MetaCart Free stores metacart.mdb under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords via a direct request. | Feb 4, 2009 | 5.0 | 15 | NO | NO |
CVE-2005-1622MEDIUM Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME paramet | May 16, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Metalinks.
Media articles that mention a CVE ID that affects a product developed by Metalinks — matched by CVE ID, not by vendor name.