CVE-2011-4567
29.11.2011, 00:55
Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.php, a different vulnerability than CVE-2011-4547.
| Vendor | Product | Version |
|---|---|---|
| zen-cart | zen_cart | 𝑥 ≤ 1.3.9 |
| zen-cart | zen_cart | 1.1.0 |
| zen-cart | zen_cart | 1.1.3 |
| zen-cart | zen_cart | 1.2.0d:d |
| zen-cart | zen_cart | 1.2.1:patch1 |
| zen-cart | zen_cart | 1.2.1d:d |
| zen-cart | zen_cart | 1.2.2d:d |
| zen-cart | zen_cart | 1.2.3d:d |
| zen-cart | zen_cart | 1.2.4.1 |
| zen-cart | zen_cart | 1.2.4d:d |
| zen-cart | zen_cart | 1.2.5d:d |
| zen-cart | zen_cart | 1.2.6d:d |
| zen-cart | zen_cart | 1.3 |
| zen-cart | zen_cart | 1.3.0.2 |
| zen-cart | zen_cart | 1.3.2 |
| zen-cart | zen_cart | 1.3.5 |
| zen-cart | zen_cart | 1.3.6 |
| zen-cart | zen_cart | 1.3.7 |
| zen-cart | zen_cart | 1.3.8 |
| zen-cart | zen_cart | 1.3.8a:a |
𝑥
= Vulnerable software versions