6.8
CVSSv2

CVE-2004-0301

Published: 23/11/2004 Updated: 11/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote malicious users to inject arbitrary HTML via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ecommerce corporation online store kit 3.0_pro

ecommerce corporation online store kit 3.0_standard

ecommerce corporation online store kit 3.0_lite

Exploits

source: wwwsecurityfocuscom/bid/9676/info Multiple vulnerabilities have been identified in the software due to improper sanitization of user-supplied input Successful exploitation of these issues could allow an attacker to carry out cross-site scripting and SQL injection attacks via the 'id' parameter of 'morephp' script Online Stor ...