CVE-2008-4121

EUVD-2008-4104
Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in a search.quick action to search.php and (2) the name parameter in a sendtofriend action to sendtofriend.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Affected Products (NVD)
VendorProductVersion
cpcommercecpcommerce
𝑥
≤ 1.2.3
cpcommercecpcommerce
0.5f:f
cpcommercecpcommerce
1.0.5
cpcommercecpcommerce
1.0.5.1
cpcommercecpcommerce
1.0.6
cpcommercecpcommerce
1.0.7
cpcommercecpcommerce
1.0.7.1
cpcommercecpcommerce
1.0.7.2
cpcommercecpcommerce
1.0.7.3
cpcommercecpcommerce
1.0.7.4
cpcommercecpcommerce
1.0.8
cpcommercecpcommerce
1.0.9
cpcommercecpcommerce
1.0.9a:a
cpcommercecpcommerce
1.1.0
cpcommercecpcommerce
1.2.0
cpcommercecpcommerce
1.2.1
cpcommercecpcommerce
1.2.2
𝑥
= Vulnerable software versions