CVE-2010-3465

XSE Shopping Cart <1.5.3.0 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.

Scores

EPSS 0.0033
EPSS Percentile 55.5%

Classification

CWE
CWE-79
Status published

Affected Products (3)

ecommercesoft/xse_shopping_cart
ecommercesoft/xse_shopping_cart
n/a/n/a

Timeline

Published Sep 17, 2010
Tracked Since Feb 18, 2026