5.8
CVE-2006-3542
- EPSS 1.35%
- Veröffentlicht 13.07.2006 00:05:00
- Zuletzt bearbeitet 16.06.2026 22:27:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown Shopping Cart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) shop name field in (a) editshop.php, (b) edititem.php, and (c) index.php; and via the (2) item field in editshop.php and edititem.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Boxcar Media ≫ Shopping Cart Version0.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.35% | 0.678 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
http://secunia.com/advisories/20957
http://securityreason.com/securityalert/1223
http://www.osvdb.org/27024
http://www.osvdb.org/27025
http://www.securityfocus.com/archive/1/439150/100/0/threaded
http://www.securityfocus.com/bid/18841
http://www.vupen.com/english/advisories/2006/2693
https://exchange.xforce.ibmcloud.com/vulnerabilities/27539