CVE-2007-3448
BugMall Shopping Cart 2.5 - Cross-Site Scripting via msgs Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3448. PoCs published by t0pP8uZz.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in Bug Mall Shopping Cart 2.5 and prior versions. It includes functional examples for both XSS via the 'msgs' parameter and SQL injection via the search box, along with default login credentials.
Description
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in Bug Mall Shopping Cart 2.5 and prior versions. It includes functional examples for both XSS via the 'msgs' parameter and SQL injection via the search box, along with default login credentials.