CVE-2008-0547
Shoppingtree Candypress Store - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by BugReport.IR · textwebappsasp
https://www.exploit-db.com/exploits/4988
References (8)
Scores
EPSS
0.0629
EPSS Percentile
90.8%
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
shoppingtree/candypress_store
shoppingtree/candypress_store
Timeline
Published
Feb 01, 2008
Tracked Since
Feb 18, 2026