CVE-2012-1413

EUVD-2012-1438
Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
Affected Products (NVD)
VendorProductVersion
zen-cartzen_cart
𝑥
≤ 1.5
zen-cartzen_cart
1.1.0
zen-cartzen_cart
1.1.3
zen-cartzen_cart
1.2.0d:d
zen-cartzen_cart
1.2.1:patch1
zen-cartzen_cart
1.2.1_patch1:_patch1
zen-cartzen_cart
1.2.1d:d
zen-cartzen_cart
1.2.2d:d
zen-cartzen_cart
1.2.3d:d
zen-cartzen_cart
1.2.4.1
zen-cartzen_cart
1.2.4d:d
zen-cartzen_cart
1.2.5d:d
zen-cartzen_cart
1.2.6d:d
zen-cartzen_cart
1.3
zen-cartzen_cart
1.3.0.2
zen-cartzen_cart
1.3.2
zen-cartzen_cart
1.3.5
zen-cartzen_cart
1.3.6
zen-cartzen_cart
1.3.7
zen-cartzen_cart
1.3.8
zen-cartzen_cart
1.3.8a:a
zen-cartzen_cart
1.3.9
zen-cartzen_cart
1.3.9h:h
𝑥
= Vulnerable software versions