CVE-2007-2790

Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the type parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vp-asp:vp-asp_shopping_cart:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:31

Type Values Removed Values Added
References () http://osvdb.org/36095 - () http://osvdb.org/36095 -
References () http://redlevel.org/wp-content/uploads/vpasp-650.txt - () http://redlevel.org/wp-content/uploads/vpasp-650.txt -
References () http://secunia.com/advisories/25314 - () http://secunia.com/advisories/25314 -
References () http://securityreason.com/securityalert/2728 - () http://securityreason.com/securityalert/2728 -
References () http://www.securityfocus.com/archive/1/468834/100/0/threaded - () http://www.securityfocus.com/archive/1/468834/100/0/threaded -
References () http://www.securitytracker.com/id?1018083 - () http://www.securitytracker.com/id?1018083 -
References () http://www.vpasp.com/helpnotes/fixes.asp?version=v650 - () http://www.vpasp.com/helpnotes/fixes.asp?version=v650 -
References () http://www.vupen.com/english/advisories/2007/1866 - () http://www.vupen.com/english/advisories/2007/1866 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/34345 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/34345 -

Information

Published : 2007-05-22 00:30

Updated : 2024-11-21 00:31


NVD link : CVE-2007-2790

Mitre link : CVE-2007-2790

CVE.ORG link : CVE-2007-2790


JSON object : View

Products Affected

vp-asp

  • vp-asp_shopping_cart