Vulnerabilities > CVE-2005-1823 - SQL Injection and Cross-Site Scripting vulnerability in Qualiteam X-Cart 4.0.8
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Qualiteam X-Cart 4.0.8 product.php Multiple Parameter XSS. CVE-2005-1823. Webapps exploit for php platform id EDB-ID:25760 last seen 2016-02-03 modified 2005-05-30 published 2005-05-30 reporter CENSORED Search Vulnerabilities source https://www.exploit-db.com/download/25760/ title Qualiteam X-Cart 4.0.8 product.php Multiple Parameter XSS description Qualiteam X-Cart 4.0.8 orders.php mode Parameter XSS. CVE-2005-1823. Webapps exploit for php platform id EDB-ID:25763 last seen 2016-02-03 modified 2005-05-30 published 2005-05-30 reporter CENSORED Search Vulnerabilities source https://www.exploit-db.com/download/25763/ title Qualiteam X-Cart 4.0.8 orders.php mode Parameter XSS description Qualiteam X-Cart 4.0.8 giftcert.php Multiple Parameter XSS. CVE-2005-1823. Webapps exploit for php platform id EDB-ID:25766 last seen 2016-02-03 modified 2005-05-30 published 2005-05-30 reporter CENSORED Search Vulnerabilities source https://www.exploit-db.com/download/25766/ title Qualiteam X-Cart 4.0.8 giftcert.php Multiple Parameter XSS description Qualiteam X-Cart 4.0.8 error_message.php id Parameter XSS. CVE-2005-1823. Webapps exploit for php platform id EDB-ID:25761 last seen 2016-02-03 modified 2005-05-30 published 2005-05-30 reporter CENSORED Search Vulnerabilities source https://www.exploit-db.com/download/25761/ title Qualiteam X-Cart 4.0.8 error_message.php id Parameter XSS description Qualiteam X-Cart 4.0.8 help.php section Parameter XSS. CVE-2005-1823. Webapps exploit for php platform id EDB-ID:25762 last seen 2016-02-03 modified 2005-05-30 published 2005-05-30 reporter CENSORED Search Vulnerabilities source https://www.exploit-db.com/download/25762/ title Qualiteam X-Cart 4.0.8 help.php section Parameter XSS
Nessus
NASL family | CGI abuses |
NASL id | QUALITEAM_XCART_SQL_XSS.NASL |
description | The remote host is running X-Cart, a PHP-based shopping cart system. The version installed on the remote host suffers from numerous SQL injection and cross-site scripting vulnerabilities. Attackers can exploit the former to influence database queries, resulting possibly in a compromise of the affected application, disclosure of sensitive data, or even attacks against the underlying database. And exploitation of the cross-site scripting flaws can be used to steal cookie-based authentication credentials and perform similar attacks. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18419 |
published | 2005-06-06 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18419 |
title | Qualiteam X-Cart Multiple Vulnerabilities |
code |
|