Логотип exploitDog
bind:CVE-2015-3421
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-3421

Количество 2

Количество 2

nvd логотип

CVE-2015-3421

больше 8 лет назад

The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-jxrm-68h4-5mgp

больше 3 лет назад

The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-3421

The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
github логотип
GHSA-jxrm-68h4-5mgp

The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу