CVE-2006-2649
Summary
| CVE | CVE-2006-2649 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-30 10:02:00 UTC |
| Updated | 2017-07-20 01:31:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, as demonstrated by the (1) query parameter in search.php and the (2) data parameter in search_cat.php. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cosmicphp | Cosmicshoppingcart | All | All | All | All |
| Application | Cosmicphp | Cosmicshoppingcart | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CosmicShoppingCart Input Validation Holes Permit Cross-Site Scripting and SQL Injection Attacks - SecurityTracker | SECTRACK | securitytracker.com | |
| 26092 | OSVDB | www.osvdb.org | |
| 26090 | OSVDB | www.osvdb.org | |
| www.zone-h.org/advisories/read/id=9058 | MISC | www.zone-h.org | Exploit, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 20060526 ZH2006-20 SA: CosmicShoppingCart Multiple Vulnerabilities | FULLDISC | archives.neohapsis.com | |
| 26093 | OSVDB | www.osvdb.org | |
| CosmicShoppingCart Multiple Input Validation Vulnerabilities | BID | www.securityfocus.com | |
| 26091 | OSVDB | www.osvdb.org | |
| CosmicShoppingCart Cross-Site Scripting and SQL Injection - Advisories - Secunia | SECUNIA | secunia.com | Exploit, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.