6.1
CVSSv3

CVE-2013-5978

Published: 11/12/2019 Updated: 16/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin prior to 1.5.1.15 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php. NOTE: This issue may only cross privilege boundaries if used in combination with CVE-2013-5977.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cart66 cart66 lite plugin

Exploits

# Exploit Title: Wordpress Cart66 Plugin 15114 Multiple Vulnerabilities # Exploit Author: absane # Blog: blognoobrootcom # Discovery date: September 29th 2013 # Vendor notified: September 29th 2013 # Vendor fixed: October 2 2013 # Vendor Homepage: cart66com # Software Link: downloadswo ...
WordPress Cart66 plugin version 15114 suffers from cross site request forgery and cross site scripting vulnerabilities ...