4.3
CVSSv2

CVE-2008-6278

Published: 25/02/2009 Updated: 26/02/2009
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote malicious users to inject arbitrary web script or HTML via the (1) category_id and (2) subcategory_id parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

rakhisoftware rakhisoftware shopping cart -

Exploits

source: wwwsecurityfocuscom/bid/32563/info RakhiSoftware Shopping Cart is prone to multiple remote vulnerabilities Exploiting these issues can allow attackers to obtain sensitive information, steal cookie data, access or modify data, or exploit latent vulnerabilities in the underlying database wwwexamplecom/rjbike_new/produc ...