Back to search
CVE-2015-2210
Published: Sep 6, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injecting Javascript into the window source to create a button that spawns a command shell.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20150502 Code Injection in Epicor Retail Store 3.2.03.01.008
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now