4.3
CVSSv2

CVE-2008-7057

Published: 24/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote malicious users to inject arbitrary HTML or web script via the type parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

grayscalecms bandsite cms 1.1.4

Exploits

########################################################################### [+] BandSite CMS 114 Arbitrary Download Database/XSS/CSRF [+] Discovered By SirGod [+] wwwmortal-teamorg [+] Greetz : EMINEM,Ras,Puscas_marin,ToxicBlood,MesSiAH,xZu,HrN ############################################## ...