Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.
References
Configurations
History
20 Nov 2024, 23:46
Type | Values Removed | Values Added |
---|---|---|
References | () http://osdir.com/ml/web.oscommerce.cvs/2003-12/msg00024.html - | |
References | () http://www.oscommerce.com/community/bugs%2C1546 - | |
References | () http://www.securityfocus.com/archive/1/347831 - | |
References | () http://www.securityfocus.com/bid/9238 - |
07 Nov 2023, 01:56
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2003-12-31 05:00
Updated : 2024-11-20 23:46
NVD link : CVE-2003-1219
Mitre link : CVE-2003-1219
CVE.ORG link : CVE-2003-1219
JSON object : View
Products Affected
oscommerce
- oscommerce
CWE