CVE-2008-1458
CS-Cart <1.3.2, <1.3.5-SP2 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in index.php in CS-Cart 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a products search action. NOTE: it was also reported that 1.3.5-SP2 trial edition is also affected.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by sasquatch · textwebappsphp
https://www.exploit-db.com/exploits/31443
References (5)
Scores
EPSS
0.0033
EPSS Percentile
55.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
cs-cart/cs-cart
cs-cart/cs-cart
Timeline
Published
Mar 24, 2008
Tracked Since
Feb 18, 2026