Turnkey Web Tools · Sunshop Shopping Cart · CVE-2007-2547
**Name of the Vulnerable Software and Affected Versions**
TurnkeyWebTools SunShop Shopping Cart version 4.0
**Description**
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `l` parameter in index.php.
**Recommendations**
For TurnkeyWebTools SunShop Shopping Cart version 4.0, consider restricting access to the `l` parameter in the index.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.