4.3
CVSSv2

CVE-2011-4567

Published: 29/11/2011 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart prior to 1.5 allows remote malicious users to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.php, a different vulnerability than CVE-2011-4547.

Vulnerable Product Search on Vulmon Subscribe to Product

zen-cart zen cart 1.3.6

zen-cart zen cart 1.3.5

zen-cart zen cart 1.2.4.1

zen-cart zen cart 1.2.2d

zen-cart zen cart 1.1.3

zen-cart zen cart 1.1.0

zen-cart zen cart 1.2.1

zen-cart zen cart 1.3.7

zen-cart zen cart 1.3.8

zen-cart zen cart

zen-cart zen cart 1.2.4d

zen-cart zen cart 1.2.0d

zen-cart zen cart 1.3.0.2

zen-cart zen cart 1.3.2

zen-cart zen cart 1.2.5d

zen-cart zen cart 1.2.3d

zen-cart zen cart 1.3

zen-cart zen cart 1.3.8a

zen-cart zen cart 1.2.1d

zen-cart zen cart 1.2.6d

Exploits

source: wwwsecurityfocuscom/bid/50787/info Zen Cart is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the cont ...