7.5
CVSSv2

CVE-2002-0553

Published: 03/07/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in SunShop 2.5 and previous versions allows remote malicious users to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.

Vulnerable Product Search on Vulmon Subscribe to Product

turnkey solutions sunshop shopping cart 1.5

turnkey solutions sunshop shopping cart 2.1

turnkey solutions sunshop shopping cart 2.4

turnkey solutions sunshop shopping cart 2.5

turnkey solutions sunshop shopping cart 2.0

turnkey solutions sunshop shopping cart 2.2

Exploits

source: wwwsecurityfocuscom/bid/4506/info SunShop is commercial web store software It is written in PHP, and will run on most Unix and Linux operating systems as well as Microsoft Windows SunShop allows attackers to embed arbitrary script code into form fields This may enable a remote attacker to perform actions as the administrative ...