CVE-2008-6044
xt-commerce < 3.0.4 - Cross-Site Scripting via Advanced Search Keywords Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6044. PoCs published by David Vieira-Kurz.
AI-analyzed exploit summary The provided text describes a session-fixation and cross-site scripting (XSS) vulnerability in xt:Commerce 3.04. It includes a proof-of-concept URL demonstrating the XSS vulnerability but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in advanced_search_result.php in xt:Commerce 3.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
Exploits (1)
The provided text describes a session-fixation and cross-site scripting (XSS) vulnerability in xt:Commerce 3.04. It includes a proof-of-concept URL demonstrating the XSS vulnerability but lacks executable exploit code.