CVE-2008-4637

Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors in the advanced search feature.  NOTE: this is probably a variant of CVE-2008-4121.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
cpcommercecpcommerce
𝑥
≤ 1.2.3
cpcommercecpcommerce
0.5f:f
cpcommercecpcommerce
1.0.5
cpcommercecpcommerce
1.0.5.1
cpcommercecpcommerce
1.0.6
cpcommercecpcommerce
1.0.7
cpcommercecpcommerce
1.0.7.1
cpcommercecpcommerce
1.0.7.2
cpcommercecpcommerce
1.0.7.3
cpcommercecpcommerce
1.0.7.4
cpcommercecpcommerce
1.0.8
cpcommercecpcommerce
1.0.9
cpcommercecpcommerce
1.0.9a:a
cpcommercecpcommerce
1.1.0
cpcommercecpcommerce
1.2.0
cpcommercecpcommerce
1.2.1
cpcommercecpcommerce
1.2.2
𝑥
= Vulnerable software versions