Shopping Cart V0.9

2006.07.14
Risk: Low
Local: No
Remote: Yes
CWE: CWE-Other


CVSS Base Score: 5.8/10
Impact Subscore: 4.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: None

Shopping Cart V0.9 Homepage: http://glendown.de/shop/ Affected files: index.php editshop.php edititem.php ----------------------------------------- XSS vuln on editshop.php & edititem.php: Data isn't sanatized before being entered. For a PoC as a shop name or item enter in: <script>alert('xss')</script> The shop names also appear on index.php, so it's affected here too.


Vote for this issue:
50%
50%

Comment it here.

Copyright 2025, cxsecurity.com

 

Back to Top