PT-2006-4032 · Edge · Edge Ecommerce Shop

Publicado

2006-06-22

·

Atualizado

2017-07-20

·

CVE-2006-3137

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Edge eCommerce Shop (affected versions not specified)
Description The issue is related to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary web script or HTML via the cart id parameter in the "productDetail.asp" page.
Recommendations For Edge eCommerce Shop, consider restricting access to the cart id parameter in the productDetail.asp page until a fix is available. As a temporary workaround, avoid using the cart id parameter in the affected page to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3137

Produtos afetados

Edge Ecommerce Shop