Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-1440
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-1440

Description:
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.

CVE Status:
Candidate

References:

ST
  1013853

SAID
  Secunia Advisory: SA15181

OSVDB
  15957
  15958
  15956
  15955
  15954
  15953
  15951
  15952

MISC
  http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html

BID
  13462


Return to the previous page.