CVE-2005-1440

ViArt Shop Enterprise 2.1.6 - Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 6 public exploits for CVE-2005-1440. PoCs published by Lostmon.

AI-analyzed exploit summary The provided text describes multiple XSS vulnerabilities in ViArt Shop due to insufficient input sanitization. It includes example URLs demonstrating how attacker-supplied script code can be injected via query parameters.

Description

Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.

Exploits (6)

exploitdb WRITEUP VERIFIED
by Lostmon · textwebappsphp
https://www.exploit-db.com/exploits/25577

The provided text describes multiple XSS vulnerabilities in ViArt Shop due to insufficient input sanitization. It includes example URLs demonstrating how attacker-supplied script code can be injected via query parameters.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: ViArt Shop Enterprise version 2.1.6
No auth needed
Prerequisites: Access to the target application's review page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Lostmon · textwebappsphp
https://www.exploit-db.com/exploits/25578

The provided text describes a cross-site scripting (XSS) vulnerability in ViArt Shop, where user-supplied input is not properly sanitized, allowing for HTML and script code injection. The example URL demonstrates how an attacker could inject malicious code via the 'category_id' parameter.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: ViArt Shop Enterprise version 2.1.6
No auth needed
Prerequisites: Access to a vulnerable ViArt Shop instance · Ability to craft a malicious URL with injected script code
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Lostmon · textwebappsphp
https://www.exploit-db.com/exploits/25579

The provided text describes XSS and HTML injection vulnerabilities in ViArt Shop due to improper input sanitization. It includes example URLs demonstrating how attacker-supplied code could be injected via the 'category_id' and 'search_string' parameters.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: ViArt Shop Enterprise version 2.1.6
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Lostmon · textwebappsphp
https://www.exploit-db.com/exploits/25576

This exploit demonstrates XSS vulnerabilities in ViArt Shop by injecting malicious scripts and HTML forms via the 'page' parameter. The PoC shows how an attacker can steal cookies or create fake login forms to phish credentials.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: ViArt Shop Enterprise version 2.1.6
No auth needed
Prerequisites: Access to a vulnerable ViArt Shop instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Lostmon · textwebappsphp
https://www.exploit-db.com/exploits/25580

The provided text describes multiple XSS vulnerabilities in ViArt Shop due to improper input sanitization. It includes example URLs demonstrating how attacker-supplied code could be injected via the 'rp' and 'page' parameters.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: ViArt Shop Enterprise version 2.1.6
No auth needed
Prerequisites: Access to crafted URLs with vulnerable parameters
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Lostmon · textwebappsphp
https://www.exploit-db.com/exploits/25575

This exploit demonstrates multiple XSS vulnerabilities in ViArt Shop by injecting malicious script code into URL parameters. The PoC provides specific URLs that can be used to trigger the vulnerabilities.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: ViArt Shop Enterprise version 2.1.6
No auth needed
Prerequisites: Access to the target application's URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13462
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15958
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013853
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15955
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15953
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15954
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15181
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15952
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15957
Exploit, Vendor Advisory vdb-entry x_refsource_osvdb
http://www.osvdb.org/15951
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15956

Scores

EPSS 0.0319
EPSS Percentile 86.4%

Details

Status published
Products (1)
codetosell/viart_shop_enterprise 2.1.6
Published May 03, 2005
Tracked Since Feb 18, 2026