CVE-2010-1486

CactuShop <6.155 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or HTML via the (1) billing address or (2) shipping address.

Exploits (1)

exploitdb WRITEUP VERIFIED
by 7Safe · textwebappsasp
https://www.exploit-db.com/exploits/12329

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39587

Scores

EPSS 0.0044
EPSS Percentile 63.2%

Details

CWE
CWE-79
Status published
Products (9)
cactushop/cactushop 3
cactushop/cactushop 4
cactushop/cactushop 4.1
cactushop/cactushop 4.5
cactushop/cactushop 4.6
cactushop/cactushop 4.7
cactushop/cactushop 5.0
cactushop/cactushop 5.1
cactushop/cactushop < 6.1
Published Apr 22, 2010
Tracked Since Feb 18, 2026