CVE-2007-0225
VP-ASP Shopping Cart <= 6.09 - Cross-Site Scripting via shopcustadmin.asp msg Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0225. PoCs published by ajann.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in VP-ASP Shopping Cart 6.09. The SQLi allows arbitrary query execution via the 'LoginLastname' parameter, while the XSS is triggered via the 'msg' parameter in 'shopcustadmin.asp'.
Description
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in VP-ASP Shopping Cart 6.09. The SQLi allows arbitrary query execution via the 'LoginLastname' parameter, while the XSS is triggered via the 'msg' parameter in 'shopcustadmin.asp'.