Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kuai Hinojosa

#52700de 53,635
3.5CVSS total
Vulnerabilidades · 1
PT-2006-5165
3.5
2006-08-25
Unknown · E-Commerce · CVE-2006-4360
**Name of the Vulnerable Software and Affected Versions** E-commerce versions prior to 4.7 with file.module version 1.37.2.4 (20060812) **Description** The issue allows remote authenticated users with the "create products" permission to inject arbitrary web script or HTML via unspecified vectors, which can lead to cross-site scripting (XSS). **Recommendations** For versions prior to 4.7 with file.module version 1.37.2.4 (20060812), update the file.module to version 1.37.2.4 (20060812) or later to resolve the issue.