Lucene search

K
cvelistMitreCVELIST:CVE-2010-1590
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-1590

2022-10-0316:21:00
mitre
www.cve.org
cross-site scripting
remote attackers
web script
html
dns hostname
cookielessgeneratefilename
cookielessreadfile

5.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.3%

Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to inject arbitrary web script or HTML via the client’s DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions.

5.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.3%

Related for CVELIST:CVE-2010-1590