4.3
CVSSv2

CVE-2012-2570

Published: 15/08/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote malicious users to inject arbitrary web script or HTML via the symb parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qualiteam x-cart 4.5

Exploits

source: wwwsecurityfocuscom/bid/54635/info The chenpress plugin for WordPress is prone to a vulnerability that lets attackers upload arbitrary files The issue occurs because the application fails to adequately sanitize user-supplied input An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of t ...
###################################################################################### # Exploit Title: X-Cart Gold 45 (products_mapphp symb parameter) XSS Vulnerability # Date: Jul 21 2012 # Author: muts # Version: X-Cart Gold 45 # Vendor URL: wwwx-cartcom/ ############################################################################### ...