Vulnerabilities > CVE-2006-5958 - Cross-Site Scripting vulnerability in infinicart

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
infinicart
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password fields in (a) login.asp, (3) search field in (b) search.asp, and (4) email field in (c) sendpassword.asp.

Vulnerable Configurations

Part Description Count
Application
Infinicart
1

Exploit-Db

  • descriptionINFINICART search.asp search Parameter XSS. CVE-2006-5958. Webapps exploit for asp platform
    idEDB-ID:28989
    last seen2016-02-03
    modified2006-11-13
    published2006-11-13
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/28989/
    titleINFINICART search.asp search Parameter XSS
  • descriptionINFINICART login.asp Multiple Parameter XSS. CVE-2006-5958. Webapps exploit for asp platform
    idEDB-ID:28991
    last seen2016-02-03
    modified2006-11-13
    published2006-11-13
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/28991/
    titleINFINICART login.asp Multiple Parameter XSS
  • descriptionINFINICART sendpassword.asp email Parameter XSS. CVE-2006-5958. Webapps exploit for asp platform
    idEDB-ID:28990
    last seen2016-02-03
    modified2006-11-13
    published2006-11-13
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/28990/
    titleINFINICART sendpassword.asp email Parameter XSS