4.3
CVSSv2

CVE-2004-1797

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the search parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

source: wwwsecurityfocuscom/bid/9359/info FreznoShop is prone to a cross-site scripting vulnerability Remote attackers may create malicious links to the software that include hostile HTML and script code If such a link was followed by a victim user, the attacker-supplied code would be rendered in the security context of the site hosting ...