PT-2008-3025 · Cs Cart · Cs-Cart

Sasquatch

+1

·

Published

2008-03-24

·

Updated

2018-10-11

·

CVE-2008-1458

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CS-Cart version 1.3.2 CS-Cart versions 1.3.5-SP2
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the q parameter in a products search action.
Recommendations For CS-Cart version 1.3.2, avoid using the q parameter in the products search action until a fix is available. For CS-Cart versions 1.3.5-SP2, restrict access to the products search action to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1458

Affected Products

Cs-Cart