Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/26065 | vdb entry |
http://www.securityfocus.com/archive/1/431983/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/17685 | vdb entry |
http://www.aria-security.net/advisory/nextage/nextageshoppingcart.txt | exploit vendor advisory |
http://securityreason.com/securityalert/791 | third party advisory |