CVE-2007-6646 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1 and possibly other versions before 1.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the return parameter to user/remindPassword (2) the q parameter to the category script (3) the return parameter to the order script or (4) the email parameter to user/remindComplete.

Reference

http://archives.neohapsis.com/archives/bugtraq/2008-02/0003.html http://livecart.com/news/Major-update-LiveCart-1-1-0.8 http://osvdb.org/39756 http://osvdb.org/39757 http://osvdb.org/39758 http://secunia.com/advisories/28017 http://securityreason.com/securityalert/3512 http://www.hackerscenter.com/archive/view.asp?id=28144 http://www.securityfocus.com/archive/1/485654/100/0/threaded http://www.securityfocus.com/bid/27087 http://www.securitytracker.com/id?1019151 https://exchange.xforce.ibmcloud.com/vulnerabilities/39305

Share on: