CVE-2009-4570 Information

Description

Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in an order/order_print action to the default URI.

Reference

http://secunia.com/advisories/31948 http://www.andreafabrizi.it/?exploits:phpshop http://www.securityfocus.com/archive/1/508270/100/0/threaded http://www.securityfocus.com/bid/37227 https://exchange.xforce.ibmcloud.com/vulnerabilities/54589

Share on: