Описание
Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter (Full Name field).
Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter (Full Name field).
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2007-2968
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34517
- http://osvdb.org/36697
- http://secunia.com/advisories/25424
- http://securityreason.com/securityalert/2761
- http://www.securityfocus.com/archive/1/469595/100/0/threaded
- http://www.securityfocus.com/bid/24166
EPSS
Процентиль: 66%
0.00507
Низкий
CVE ID
Связанные уязвимости
nvd
больше 18 лет назад
Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter (Full Name field).
EPSS
Процентиль: 66%
0.00507
Низкий