CVE Database
/

CVE-2007-6646

Back to search

CVE-2007-6646

Published: Jan 4, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1, and possibly other versions before 1.1.0, allow remote attackers to inject arbitrary web script or HTML via (1) the return parameter to user/remindPassword, (2) the q parameter to the category script, (3) the return parameter to the order script, or (4) the email parameter to user/remindComplete.

VendorProductVersions

n/a

n/a

affected
n/a

References

27087
vdb-entry
x_refsource_BID
3512
third-party-advisory
x_refsource_SREASON
39756
vdb-entry
x_refsource_OSVDB
39758
vdb-entry
x_refsource_OSVDB
livecart-multiple-xss(39305)
vdb-entry
x_refsource_XF
39757
vdb-entry
x_refsource_OSVDB
28017
third-party-advisory
x_refsource_SECUNIA
1019151
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now