4.3
CVSSv2

CVE-2007-3324

Published: 21/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote malicious users to inject arbitrary web script or HTML via the redirectUrl parameter to (1) comersus_customerAuthenticateForm.asp or (2) comersus_message.asp, different vectors than CVE-2004-0681.

Vulnerable Product Search on Vulmon Subscribe to Product

comersus open technologies comersus cart 7.07

Exploits

source: wwwsecurityfocuscom/bid/24562/info Comersus Cart is affected by multiple input validation vulnerabilities A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database The attacker may also leverage this issue to execute arbitrary ...
source: wwwsecurityfocuscom/bid/24562/info Comersus Cart is affected by multiple input validation vulnerabilities A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database The attacker may also leverage this issue to execute arbitrary cod ...