Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/16535 | vdb entry |
http://www.securityfocus.com/bid/10617 | vdb entry exploit |
http://marc.info/?l=bugtraq&m=108887778628398&w=2 | mailing list |
http://drponidi.5u.com/advisory.htm |