CVE-2011-0504 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6 1.6.1 and probably earlier versions llow remote attackers to inject arbitrary web script or HTML via the (1) status parameter to admin/orders.php (2) search parameter to admin/customers.php or (3) STORE_NAME parameter to admin/configuration.php.

Reference

http://osvdb.org/70429 http://osvdb.org/70430 http://secunia.com/advisories/42869 http://www.exploit-db.com/exploits/15968 http://www.htbridge.ch/advisory/xss_vulnerability_in_vam_shop.html http://www.htbridge.ch/advisory/xss_vulnerability_in_vam_shop_1.html http://www.htbridge.ch/advisory/xss_vulnerability_in_vam_shop_2.html http://www.securityfocus.com/archive/1/515615/100/0/threaded http://www.securityfocus.com/archive/1/515619/100/0/threaded http://www.securityfocus.com/archive/1/515620/100/0/threaded

Share on: