PT-2005-4648 · Ghostscript · Ghostscripter Amazon Shop
Published
2005-11-30
·
Updated
2011-03-08
·
CVE-2005-3908
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
GhostScripter Amazon Shop versions 5.0.0 through 5.0.1
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject web script or HTML. This is achieved via the query parameter in the search.php file.
Recommendations
For GhostScripter Amazon Shop versions 5.0.0 through 5.0.1, update to version 5.0.2 or later to resolve the issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostscripter Amazon Shop