PT-2005-2498 · Midicart · Midicart Php Shopping Cart

Exoduks

·

Published

2005-05-11

·

Updated

2017-07-11

·

CVE-2005-1502

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MidiCart PHP Shopping Cart (affected versions not specified)
Description The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML. The injection can occur via the searchstring parameter to 'search list.php', or the secondgroup or maingroup parameters to 'item list.php'.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1502

Affected Products

Midicart Php Shopping Cart