2.6
CVSSv2

CVE-2012-1413

Published: 27/05/2012 Updated: 28/05/2012
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and previous versions, when the software is being installed, allows remote malicious users to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

zen-cart zen cart 1.3.9

zen-cart zen cart 1.2.3d

zen-cart zen cart 1.3.7

zen-cart zen cart 1.3.0.2

zen-cart zen cart 1.3.2

zen-cart zen cart

zen-cart zen cart 1.2.1

zen-cart zen cart 1.2.6d

zen-cart zen cart 1.3.6

zen-cart zen cart 1.2.4d

zen-cart zen cart 1.1.3

zen-cart zen cart 2008

zen-cart zen cart 1.3.9h

zen-cart zen cart 1.2.1d

zen-cart zen cart 1.3.5

zen-cart zen cart 1.2.1_patch1

zen-cart zen cart 1.2.4.1

zen-cart zen cart 1.2.2d

zen-cart zen cart 1.2.5d

zen-cart zen cart 1.2.0d

zen-cart zen cart 1.3

zen-cart zen cart 1.3.8a

zen-cart zen cart 1.1.0

zen-cart zen cart 1.3.8