CVE-2012-1413

Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
zen-cartzen_cart
𝑥
≤ 1.5
zen-cartzen_cart
1.1.0
zen-cartzen_cart
1.1.3
zen-cartzen_cart
1.2.0d:d
zen-cartzen_cart
1.2.1:patch1
zen-cartzen_cart
1.2.1_patch1:_patch1
zen-cartzen_cart
1.2.1d:d
zen-cartzen_cart
1.2.2d:d
zen-cartzen_cart
1.2.3d:d
zen-cartzen_cart
1.2.4.1
zen-cartzen_cart
1.2.4d:d
zen-cartzen_cart
1.2.5d:d
zen-cartzen_cart
1.2.6d:d
zen-cartzen_cart
1.3
zen-cartzen_cart
1.3.0.2
zen-cartzen_cart
1.3.2
zen-cartzen_cart
1.3.5
zen-cartzen_cart
1.3.6
zen-cartzen_cart
1.3.7
zen-cartzen_cart
1.3.8
zen-cartzen_cart
1.3.8a:a
zen-cartzen_cart
1.3.9
zen-cartzen_cart
1.3.9h:h
𝑥
= Vulnerable software versions