4.3
CVSSv2

CVE-2010-1486

Published: 22/04/2010 Updated: 26/05/2010
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop prior to 6.155 allow remote malicious users to inject arbitrary web script or HTML via the (1) billing address or (2) shipping address.

Vulnerable Product Search on Vulmon Subscribe to Product

cactushop cactushop 4.5

cactushop cactushop 4.6

cactushop cactushop 4.7

cactushop cactushop 5.0

cactushop cactushop 4

cactushop cactushop

cactushop cactushop 3

cactushop cactushop 4.1

cactushop cactushop 5.1

Exploits

User Invoices Persistent XSS Vulnerability in CactuShop 1 Advisory Information Title: User Invoices Persistent XSS Vulnerability in CactuShop Advisory Id: CORE-2010-0406 Advisory URL: wwwcoresecuritycom/content/cactushop-xss-persistent-vulnerability Date published: 2010-04-20 Date of last update: 2010-04-20 Vendors contacted: Cactusoft ...
Core Security Technologies Advisory - A Cross Site Scripting (XSS) vulnerability has been discovered in CactuShop ...