6.8
CVSSv2

CVE-2007-0056

Published: 04/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 710
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote malicious users to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ashopsoftware ashop administration panel

ashopsoftware ashop deluxe 4.5

Exploits

source: wwwsecurityfocuscom/bid/21845/info AShop Deluxe and AShop Administration Panel are prone to multiple cross-site scripting vulnerabilities because they fail to sufficiently sanitize user-supplied input data An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in th ...
source: wwwsecurityfocuscom/bid/21845/info AShop Deluxe and AShop Administration Panel are prone to multiple cross-site scripting vulnerabilities because they fail to sufficiently sanitize user-supplied input data An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the ...
source: wwwsecurityfocuscom/bid/21845/info AShop Deluxe and AShop Administration Panel are prone to multiple cross-site scripting vulnerabilities because they fail to sufficiently sanitize user-supplied input data An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the co ...
source: wwwsecurityfocuscom/bid/21845/info AShop Deluxe and AShop Administration Panel are prone to multiple cross-site scripting vulnerabilities because they fail to sufficiently sanitize user-supplied input data An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user i ...
source: wwwsecurityfocuscom/bid/21845/info AShop Deluxe and AShop Administration Panel are prone to multiple cross-site scripting vulnerabilities because they fail to sufficiently sanitize user-supplied input data An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user ...
source: wwwsecurityfocuscom/bid/21845/info AShop Deluxe and AShop Administration Panel are prone to multiple cross-site scripting vulnerabilities because they fail to sufficiently sanitize user-supplied input data An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in ...