PT-2006-4032 · Edge · Edge Ecommerce Shop

Published

2006-06-22

·

Updated

2017-07-20

·

CVE-2006-3137

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Edge eCommerce Shop (affected versions not specified)
Description The issue is related to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary web script or HTML via the cart id parameter in the "productDetail.asp" page.
Recommendations For Edge eCommerce Shop, consider restricting access to the cart id parameter in the productDetail.asp page until a fix is available. As a temporary workaround, avoid using the cart id parameter in the affected page to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3137

Affected Products

Edge Ecommerce Shop