CVE-2003-1219
osCommerce < 2.2_ms2 - Cross-Site Scripting via osCsid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1219. PoCs published by JeiAr.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in osCommerce, where an attacker can craft a malicious URL to inject HTML or script code. The example URL demonstrates the vulnerability but does not include executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in osCommerce, where an attacker can craft a malicious URL to inject HTML or script code. The example URL demonstrates the vulnerability but does not include executable exploit code.