CVE Database
/

CVE-2005-1823

Back to search

CVE-2005-1823

Published: Jun 1, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

1014077
vdb-entry
x_refsource_SECTRACK
xcart-multiple-scripts-xss(20774)
vdb-entry
x_refsource_XF
13817
vdb-entry
x_refsource_BID
15555
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now