CVE-2008-6758

Viart Shop - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6758.

AI-analyzed exploit summary The document details multiple vulnerabilities in ViArt Shopping Cart v3.5, including full path disclosure, information disclosure, and arbitrary code injection via XSS. It provides technical descriptions of attack vectors and their impacts but does not include functional exploit code.

Description

Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/7628

The document details multiple vulnerabilities in ViArt Shopping Cart v3.5, including full path disclosure, information disclosure, and arbitrary code injection via XSS. It provides technical descriptions of attack vectors and their impacts but does not include functional exploit code.

Classification
Writeup 95%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ViArt Shopping Cart v3.5
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/53283
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/499625/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/51029
Exploit vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021497
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33340
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33043

Scores

EPSS 0.0096
EPSS Percentile 57.0%

Details

CWE
CWE-352
Status published
Products (1)
viart/viart_shop 3.5
Published Apr 28, 2009
Tracked Since Feb 18, 2026