Vulnerabilities > CVE-2004-2109 - Cross-Site Scripting vulnerability in QuadComm Q-Shop
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL network
quadcomm
Summary
Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |