Turnkey Solutions' vulnerability profile centers on the SunShop shopping cart product, a web-based e-commerce platform that handles customer transactions and data. The recurring weakness classes point to input-handling issues, most notably SQL injection, which reflects the application's reliance on database interaction and the need for rigorous input validation at the application tier. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Turnkey Solutions over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0553HIGH Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new cu | Jul 3, 2002 | 7.5 | 29 | NO | YES |
CVE-2006-2124MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) | May 1, 2006 | 5.8 | 24 | NO | YES |
CVE-2008-2038MEDIUM Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL c | Apr 30, 2008 | 6.5 | 17 | NO | NO |
CVE-2005-4787MEDIUM Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex | Dec 31, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Turnkey Solutions.
Media articles that mention a CVE ID that affects a product developed by Turnkey Solutions — matched by CVE ID, not by vendor name.