CVE-2010-3465
XSE Shopping Cart <1.5.3.0 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.
References (5)
Scores
EPSS
0.0033
EPSS Percentile
55.5%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
ecommercesoft/xse_shopping_cart
ecommercesoft/xse_shopping_cart
n/a/n/a
Timeline
Published
Sep 17, 2010
Tracked Since
Feb 18, 2026