Vulnerabilities > CVE-2005-1440 - Cross-Site Scripting and HTML Injection vulnerability in Codetosell Viart Shop Enterprise 2.1.6

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
codetosell
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.

Vulnerable Configurations

Part Description Count
Application
Codetosell
1

Exploit-Db

  • descriptionCodetoSell ViArt Shop Enterprise 2.1.6 products.php Multiple Parameter XSS. CVE-2005-1440 . Webapps exploit for php platform
    idEDB-ID:25579
    last seen2016-02-03
    modified2005-05-02
    published2005-05-02
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25579/
    titleCodetoSell ViArt Shop Enterprise 2.1.6 products.php Multiple Parameter XSS
  • descriptionCodetoSell ViArt Shop Enterprise 2.1.6 basket.php Multiple Parameter XSS. CVE-2005-1440. Webapps exploit for php platform
    idEDB-ID:25575
    last seen2016-02-03
    modified2005-05-02
    published2005-05-02
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25575/
    titleCodetoSell ViArt Shop Enterprise 2.1.6 basket.php Multiple Parameter XSS
  • descriptionCodetoSell ViArt Shop Enterprise 2.1.6 news_view.php Multiple Parameter XSS. CVE-2005-1440. Webapps exploit for php platform
    idEDB-ID:25580
    last seen2016-02-03
    modified2005-05-02
    published2005-05-02
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25580/
    titleCodetoSell ViArt Shop Enterprise 2.1.6 news_view.php Multiple Parameter XSS
  • descriptionCodetoSell ViArt Shop Enterprise 2.1.6 reviews.php Multiple Parameter XSS. CVE-2005-1440. Webapps exploit for php platform
    idEDB-ID:25577
    last seen2016-02-03
    modified2005-05-02
    published2005-05-02
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25577/
    titleCodetoSell ViArt Shop Enterprise 2.1.6 reviews.php Multiple Parameter XSS
  • descriptionCodetoSell ViArt Shop Enterprise 2.1.6 page.php page Parameter XSS. CVE-2005-1440 . Webapps exploit for php platform
    idEDB-ID:25576
    last seen2016-02-03
    modified2005-05-02
    published2005-05-02
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25576/
    titleCodetoSell ViArt Shop Enterprise 2.1.6 page.php page Parameter XSS