CVE-2008-4121

Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in a search.quick action to search.php and (2) the name parameter in a sendtofriend action to sendtofriend.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
cpcommercecpcommerce
𝑥
≤ 1.2.3
cpcommercecpcommerce
0.5f:f
cpcommercecpcommerce
1.0.5
cpcommercecpcommerce
1.0.5.1
cpcommercecpcommerce
1.0.6
cpcommercecpcommerce
1.0.7
cpcommercecpcommerce
1.0.7.1
cpcommercecpcommerce
1.0.7.2
cpcommercecpcommerce
1.0.7.3
cpcommercecpcommerce
1.0.7.4
cpcommercecpcommerce
1.0.8
cpcommercecpcommerce
1.0.9
cpcommercecpcommerce
1.0.9a:a
cpcommercecpcommerce
1.1.0
cpcommercecpcommerce
1.2.0
cpcommercecpcommerce
1.2.1
cpcommercecpcommerce
1.2.2
𝑥
= Vulnerable software versions