Record summary

CVE-2012-4236 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source before 2.1.2_p1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBTotal Shop UK eCommerce CodeIgniter - Multiple Cross-Site Scripting VulnerabilitiesExploitDB exploitby Chris CooperNot analyzed1 file
ExploitDB

PoC details

References

5