CVE-2002-0439

Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field.
Configurations

Configuration 1 (hide)

cpe:2.3:a:caupo.net:cauposhop:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:39

Type Values Removed Values Added
References () http://www.iss.net/security_center/static/8431.php - Patch () http://www.iss.net/security_center/static/8431.php - Patch
References () http://www.securityfocus.com/archive/1/261218 - () http://www.securityfocus.com/archive/1/261218 -
References () http://www.securityfocus.com/bid/4270 - Patch () http://www.securityfocus.com/bid/4270 - Patch

Information

Published : 2002-07-26 04:00

Updated : 2024-11-20 23:39


NVD link : CVE-2002-0439

Mitre link : CVE-2002-0439

CVE.ORG link : CVE-2002-0439


JSON object : View

Products Affected

caupo.net

  • cauposhop