Lucene search

K
cveMitreCVE-2013-7317
HistoryJan 24, 2014 - 3:08 p.m.

CVE-2013-7317

2014-01-2415:08:00
CWE-79
mitre
web.nvd.nist.gov
24
cve-2013-7317
cross-site scripting
xss
cs-cart
vulnerabilities
security advisory
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.003

Percentile

65.6%

Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) settings_file or (2) data_file parameter to (a) ampie.swf, (b) amline.swf, or © amcolumn.swf.

Affected configurations

Nvd
Node
cs-cartcs-cartRange4.0.3
OR
cs-cartcs-cartMatch1.3.0
OR
cs-cartcs-cartMatch1.3.2
OR
cs-cartcs-cartMatch1.3.3
OR
cs-cartcs-cartMatch1.3.4
OR
cs-cartcs-cartMatch2.0
OR
cs-cartcs-cartMatch2.0.5
OR
cs-cartcs-cartMatch2.0.6
OR
cs-cartcs-cartMatch2.0.7
OR
cs-cartcs-cartMatch2.0.8
OR
cs-cartcs-cartMatch2.0.9
OR
cs-cartcs-cartMatch2.0.10
OR
cs-cartcs-cartMatch2.0.11
OR
cs-cartcs-cartMatch2.0.12
OR
cs-cartcs-cartMatch2.0.13
OR
cs-cartcs-cartMatch2.0.14
OR
cs-cartcs-cartMatch2.0.15
OR
cs-cartcs-cartMatch2.1
OR
cs-cartcs-cartMatch2.1.1
OR
cs-cartcs-cartMatch2.1.2
OR
cs-cartcs-cartMatch2.1.3
OR
cs-cartcs-cartMatch2.1.4
OR
cs-cartcs-cartMatch2.2.1
OR
cs-cartcs-cartMatch2.2.2
OR
cs-cartcs-cartMatch2.2.3
OR
cs-cartcs-cartMatch2.2.4
OR
cs-cartcs-cartMatch2.2.5
OR
cs-cartcs-cartMatch3.0
OR
cs-cartcs-cartMatch3.0.2
OR
cs-cartcs-cartMatch3.0.3
OR
cs-cartcs-cartMatch3.0.4
OR
cs-cartcs-cartMatch3.0.5
OR
cs-cartcs-cartMatch3.0.6
OR
cs-cartcs-cartMatch4.0
OR
cs-cartcs-cartMatch4.0.2
VendorProductVersionCPE
cs-cartcs-cart*cpe:2.3:a:cs-cart:cs-cart:*:*:*:*:*:*:*:*
cs-cartcs-cart1.3.0cpe:2.3:a:cs-cart:cs-cart:1.3.0:*:*:*:*:*:*:*
cs-cartcs-cart1.3.2cpe:2.3:a:cs-cart:cs-cart:1.3.2:*:*:*:*:*:*:*
cs-cartcs-cart1.3.3cpe:2.3:a:cs-cart:cs-cart:1.3.3:*:*:*:*:*:*:*
cs-cartcs-cart1.3.4cpe:2.3:a:cs-cart:cs-cart:1.3.4:*:*:*:*:*:*:*
cs-cartcs-cart2.0cpe:2.3:a:cs-cart:cs-cart:2.0:*:*:*:*:*:*:*
cs-cartcs-cart2.0.5cpe:2.3:a:cs-cart:cs-cart:2.0.5:*:*:*:*:*:*:*
cs-cartcs-cart2.0.6cpe:2.3:a:cs-cart:cs-cart:2.0.6:*:*:*:*:*:*:*
cs-cartcs-cart2.0.7cpe:2.3:a:cs-cart:cs-cart:2.0.7:*:*:*:*:*:*:*
cs-cartcs-cart2.0.8cpe:2.3:a:cs-cart:cs-cart:2.0.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 351

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.003

Percentile

65.6%

Related for CVE-2013-7317