CVE-2006-2979 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5 and possibly other distributions including Light Standard and Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter in forum.php which is not properly handled in block_forum_topics.php and (2) item_id parameter in reviews.php which is not properly handled in block_reviews.php.

Reference

http://secunia.com/advisories/20538 http://securityreason.com/securityalert/1087 http://www.attrition.org/pipermail/vim/2006-June/000846.html http://www.codetosell.com/downloads/xss_fix.zip http://www.securityfocus.com/archive/1/436415/100/0/threaded http://www.securityfocus.com/bid/18369 http://www.vupen.com/english/advisories/2006/2253 https://exchange.xforce.ibmcloud.com/vulnerabilities/27112

Share on: