7.5
CVSSv2

CVE-2001-1199

Published: 17/12/2001 Updated: 14/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in agora.cgi for Agora 3.0a up to and including 4.0g, when debug mode is enabled, allows remote malicious users to execute Javascript on other clients via the cart_id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

steve kneizys agora.cgi 4.0d

steve kneizys agora.cgi 3.3e

steve kneizys agora.cgi 3.3b

steve kneizys agora.cgi 3.3c

steve kneizys agora.cgi 3.2f

steve kneizys agora.cgi 3.2r

steve kneizys agora.cgi 3.2

steve kneizys agora.cgi 3.3j

steve kneizys agora.cgi 3.2l

steve kneizys agora.cgi 3.2k

steve kneizys agora.cgi 3.2d

steve kneizys agora.cgi 3.2p

steve kneizys agora.cgi 3.2j

steve kneizys agora.cgi 3.2ja

steve kneizys agora.cgi 3.2e

steve kneizys agora.cgi 4.0b

steve kneizys agora.cgi 3.2g

steve kneizys agora.cgi 3.2b

steve kneizys agora.cgi 3.3f

steve kneizys agora.cgi 3.2m

steve kneizys agora.cgi 3.3i

steve kneizys agora.cgi 4.0

steve kneizys agora.cgi 3.2a

steve kneizys agora.cgi 3.2q

steve kneizys agora.cgi 3.3a

steve kneizys agora.cgi 4.0a

steve kneizys agora.cgi 3.2i

steve kneizys agora.cgi 3.2n

steve kneizys agora.cgi 3.2h

steve kneizys agora.cgi 3.2c

steve kneizys agora.cgi 3.3d

steve kneizys agora.cgi 4.0c

Exploits

source: wwwsecurityfocuscom/bid/3702/info Agoracgi is a freely available, open source shopping cart system When debug mode is enabled, the Agoracgi script does not adequately filter HTML tags when debug information is being output Debug mode is not enabled by default and must be explicitly turned on by an administrator As a result, ...