2.6

CVE-2012-1413

Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.

Data is provided by the National Vulnerability Database (NVD)
Zen-cartZen Cart Version <= 1.5
Zen-cartZen Cart Version1.1.0
Zen-cartZen Cart Version1.1.3
Zen-cartZen Cart Version1.2.0d
Zen-cartZen Cart Version1.2.1 Updatepatch1
Zen-cartZen Cart Version1.2.1_patch1
Zen-cartZen Cart Version1.2.1d
Zen-cartZen Cart Version1.2.2d
Zen-cartZen Cart Version1.2.3d
Zen-cartZen Cart Version1.2.4.1
Zen-cartZen Cart Version1.2.4d
Zen-cartZen Cart Version1.2.5d
Zen-cartZen Cart Version1.2.6d
Zen-cartZen Cart Version1.3
Zen-cartZen Cart Version1.3.0.2
Zen-cartZen Cart Version1.3.2
Zen-cartZen Cart Version1.3.5
Zen-cartZen Cart Version1.3.6
Zen-cartZen Cart Version1.3.7
Zen-cartZen Cart Version1.3.8
Zen-cartZen Cart Version1.3.8a
Zen-cartZen Cart Version1.3.9
Zen-cartZen Cart Version1.3.9h
Zen-cartZen Cart Version2008
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.23% 0.423
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.