Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or HTML via the (1) billing address or (2) shipping address.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cactushop | Cactushop | <= 6.1 |
Related Weaknesses (CWE)
References
- http://www.coresecurity.com/content/cactushop-xss-persistent-vulnerability
- http://www.securityfocus.com/bid/39587
- http://www.coresecurity.com/content/cactushop-xss-persistent-vulnerability
- http://www.securityfocus.com/bid/39587
FAQ
What is CVE-2010-1486?
CVE-2010-1486 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or HTML via the (1) billing address or (2) shipping ...
How severe is CVE-2010-1486?
CVE-2010-1486 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-1486?
Check the references section above for vendor advisories and patch information. Affected products include: Cactushop Cactushop.