CVE-2010-1541

Multiple cross-site scripting (XSS) vulnerabilities in DFD Cart 1.198, 1.197, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category and (2) list_quantity parameters to index.php, and the (3) category parameter to your.order.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
dragonfrugaldfd_cart
𝑥
≤ 1.198
dragonfrugaldfd_cart
1.1.4
dragonfrugaldfd_cart
1.1.5
dragonfrugaldfd_cart
1.1.6
dragonfrugaldfd_cart
1.1.7
dragonfrugaldfd_cart
1.1.8
dragonfrugaldfd_cart
1.192
dragonfrugaldfd_cart
1.193
dragonfrugaldfd_cart
1.194
dragonfrugaldfd_cart
1.195
dragonfrugaldfd_cart
1.196
dragonfrugaldfd_cart
1.197
𝑥
= Vulnerable software versions