CVE-2011-4567
29.11.2011, 00:55
Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.php, a different vulnerability than CVE-2011-4547.
Vendor | Product | Version |
---|---|---|
zen-cart | zen_cart | 𝑥 ≤ 1.3.9 |
zen-cart | zen_cart | 1.1.0 |
zen-cart | zen_cart | 1.1.3 |
zen-cart | zen_cart | 1.2.0d:d |
zen-cart | zen_cart | 1.2.1:patch1 |
zen-cart | zen_cart | 1.2.1d:d |
zen-cart | zen_cart | 1.2.2d:d |
zen-cart | zen_cart | 1.2.3d:d |
zen-cart | zen_cart | 1.2.4.1 |
zen-cart | zen_cart | 1.2.4d:d |
zen-cart | zen_cart | 1.2.5d:d |
zen-cart | zen_cart | 1.2.6d:d |
zen-cart | zen_cart | 1.3 |
zen-cart | zen_cart | 1.3.0.2 |
zen-cart | zen_cart | 1.3.2 |
zen-cart | zen_cart | 1.3.5 |
zen-cart | zen_cart | 1.3.6 |
zen-cart | zen_cart | 1.3.7 |
zen-cart | zen_cart | 1.3.8 |
zen-cart | zen_cart | 1.3.8a:a |
𝑥
= Vulnerable software versions