CVE-2009-2587 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php the (2) prefix parameter to includes/ajax/getstate.php the search parameter to (3) index.php and (4) search.php the (5) redirect parameter to login.php and the (6) product parameter to productdetail.php.
Reference
http://packetstormsecurity.org/0907-exploits/dragdopcart-xss.txt http://secunia.com/advisories/35925 http://www.osvdb.org/56065 http://www.osvdb.org/56066 http://www.osvdb.org/56067 http://www.osvdb.org/56069 http://www.osvdb.org/56070 http://www.osvdb.org/56071 https://exchange.xforce.ibmcloud.com/vulnerabilities/51877
Share on: