20020413 SunSop: cross-site-scripting bugmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-04/0154.html CVE-2002-0553
SunShop Shopping Cart 1.5/2.x - User-Embedded Scripting
Record summary
CVE-2002-0553 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSunShop Shopping Cart 1.5/2.x - User-Embedded ScriptingExploitDB exploitby ppp-designNot analyzed1 file
References
4sunshop-new-cust-css(8840)vdb entry
http://www.iss.net/security_center/static/8840.php 4506vdb entry
http://www.securityfocus.com/bid/4506 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0553