CVE-2008-6616
Zen Cart 2008 - Cross-Site Scripting via Advanced Search Keyword Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6616. PoCs published by Ivan Sanchez.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in Zen Cart by injecting a malicious script via the 'keyword' parameter in the URL. The payload is delivered through a crafted URL that bypasses insufficient input sanitization.
Description
Cross-site scripting (XSS) vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in the advanced_search_result page. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in Zen Cart by injecting a malicious script via the 'keyword' parameter in the URL. The payload is delivered through a crafted URL that bypasses insufficient input sanitization.