Vulnerabilities > CVE-2004-2109 - Cross-Site Scripting vulnerability in QuadComm Q-Shop

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
quadcomm

Summary

Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL.

Vulnerable Configurations

Part Description Count
Application
Quadcomm
4