Lucene search

K
cve[email protected]CVE-2011-5104
HistoryAug 23, 2012 - 8:55 p.m.

CVE-2011-5104

2012-08-2320:55:02
CWE-79
web.nvd.nist.gov
17
cve-2011-5104
cross-site scripting
xss
wp e-commerce
wordpress
remote attack
arbitrary web script
html
sales logs
security vulnerability

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.7%

Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possibly earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_text parameter. NOTE: some of these details are obtained from third party information.

Affected configurations

NVD
Node
getshoppedwp_e-commerceRange3.8.7.1
OR
getshoppedwp_e-commerceMatch3.6.5
OR
getshoppedwp_e-commerceMatch3.6.6
OR
getshoppedwp_e-commerceMatch3.6.7
OR
getshoppedwp_e-commerceMatch3.6.8
OR
getshoppedwp_e-commerceMatch3.6.9
OR
getshoppedwp_e-commerceMatch3.6.10
OR
getshoppedwp_e-commerceMatch3.6.11
OR
getshoppedwp_e-commerceMatch3.6.12
OR
getshoppedwp_e-commerceMatch3.6.13
OR
getshoppedwp_e-commerceMatch3.7
OR
getshoppedwp_e-commerceMatch3.7beta2
OR
getshoppedwp_e-commerceMatch3.7beta3
OR
getshoppedwp_e-commerceMatch3.7.1
OR
getshoppedwp_e-commerceMatch3.7.2
OR
getshoppedwp_e-commerceMatch3.7.3
OR
getshoppedwp_e-commerceMatch3.7.4
OR
getshoppedwp_e-commerceMatch3.7.5
OR
getshoppedwp_e-commerceMatch3.7.5beta1
OR
getshoppedwp_e-commerceMatch3.7.5beta2
OR
getshoppedwp_e-commerceMatch3.7.5rc1
OR
getshoppedwp_e-commerceMatch3.7.5rc2
OR
getshoppedwp_e-commerceMatch3.7.5rc3
OR
getshoppedwp_e-commerceMatch3.7.5rc4
OR
getshoppedwp_e-commerceMatch3.7.5.1
OR
getshoppedwp_e-commerceMatch3.7.5.1beta
OR
getshoppedwp_e-commerceMatch3.7.5.2
OR
getshoppedwp_e-commerceMatch3.7.5.3
OR
getshoppedwp_e-commerceMatch3.7.6
OR
getshoppedwp_e-commerceMatch3.7.6rc1
OR
getshoppedwp_e-commerceMatch3.7.6rc2
OR
getshoppedwp_e-commerceMatch3.7.6rc3
OR
getshoppedwp_e-commerceMatch3.7.6rc4
OR
getshoppedwp_e-commerceMatch3.7.6.1
OR
getshoppedwp_e-commerceMatch3.7.6.2
OR
getshoppedwp_e-commerceMatch3.7.6.3
OR
getshoppedwp_e-commerceMatch3.7.6.4
OR
getshoppedwp_e-commerceMatch3.7.6.5
OR
getshoppedwp_e-commerceMatch3.7.6.6
OR
getshoppedwp_e-commerceMatch3.7.6.7
OR
getshoppedwp_e-commerceMatch3.7.6.9
OR
getshoppedwp_e-commerceMatch3.7.7
OR
getshoppedwp_e-commerceMatch3.7.8
OR
getshoppedwp_e-commerceMatch3.7.8.1
OR
getshoppedwp_e-commerceMatch3.7.8.2
OR
getshoppedwp_e-commerceMatch3.7.8.3
OR
getshoppedwp_e-commerceMatch3.8
OR
getshoppedwp_e-commerceMatch3.8beta1
OR
getshoppedwp_e-commerceMatch3.8beta2
OR
getshoppedwp_e-commerceMatch3.8beta3
OR
getshoppedwp_e-commerceMatch3.8rc1
OR
getshoppedwp_e-commerceMatch3.8rc2
OR
getshoppedwp_e-commerceMatch3.8rc3
OR
getshoppedwp_e-commerceMatch3.8rc4
OR
getshoppedwp_e-commerceMatch3.8.1
OR
getshoppedwp_e-commerceMatch3.8.2
OR
getshoppedwp_e-commerceMatch3.8.3
OR
getshoppedwp_e-commerceMatch3.8.4
OR
getshoppedwp_e-commerceMatch3.8.5
OR
getshoppedwp_e-commerceMatch3.8.6
OR
getshoppedwp_e-commerceMatch3.8.6.1
OR
getshoppedwp_e-commerceMatch3.8.7
AND
wordpresswordpressMatch-

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.7%

Related for CVE-2011-5104