4.3
CVSSv2

CVE-2011-5104

Published: 23/08/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possibly earlier for WordPress allows remote malicious users to inject arbitrary web script or HTML via the custom_text parameter. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

getshopped wp_e-commerce 3.8.6

getshopped wp_e-commerce 3.8.5

getshopped wp_e-commerce 3.8

getshopped wp_e-commerce 3.7.8.1

getshopped wp_e-commerce 3.7.8

getshopped wp_e-commerce 3.7.7

getshopped wp_e-commerce 3.7.6.2

getshopped wp_e-commerce 3.7.6.1

getshopped wp_e-commerce 3.7

getshopped wp_e-commerce 3.7.5.3

getshopped wp_e-commerce 3.7.5

getshopped wp_e-commerce 3.6.13

getshopped wp_e-commerce 3.6.12

getshopped wp_e-commerce 3.8.4

getshopped wp_e-commerce 3.8.3

getshopped wp_e-commerce 3.7.6.9

getshopped wp_e-commerce 3.7.6.7

getshopped wp_e-commerce 3.7.6

getshopped wp_e-commerce 3.7.5.2

getshopped wp_e-commerce 3.7.5.1

getshopped wp_e-commerce 3.7.4

getshopped wp_e-commerce 3.6.11

getshopped wp_e-commerce 3.6.10

getshopped wp_e-commerce 3.6.5

getshopped wp_e-commerce 3.8.7

getshopped wp_e-commerce 3.8.6.1

getshopped wp_e-commerce 3.7.8.3

getshopped wp_e-commerce 3.7.8.2

getshopped wp_e-commerce 3.7.6.4

getshopped wp_e-commerce 3.7.6.3

getshopped wp_e-commerce 3.7.1

getshopped wp_e-commerce 3.6.7

getshopped wp_e-commerce 3.6.6

getshopped wp_e-commerce

getshopped wp_e-commerce 3.8.2

getshopped wp_e-commerce 3.8.1

getshopped wp_e-commerce 3.7.6.6

getshopped wp_e-commerce 3.7.6.5

getshopped wp_e-commerce 3.7.3

getshopped wp_e-commerce 3.7.2

getshopped wp_e-commerce 3.6.9

getshopped wp_e-commerce 3.6.8