Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver2 2.1.2a and earlier, EC-CUBE Ver2 Beta(RC) 2.2.0-beta and earlier, and EC-CUBE Community Edition Nighly-Build r17623 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4536 and CVE-2008-4537.
References 6 Total
- securityfocus.com: 31509 vdb-entry
- jvndb.jvn.jp: JVNDB-2008-000064 third-party-advisory
- jvn.jp: JVN#99916563 third-party-advisory
- exchange.xforce.ibmcloud.com: eccube-multiple-unspecified-xss(45591) vdb-entry
- http://www.ec-cube.net/release/detail.php?release_id=193
- secunia.com: 32065 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- securityfocus.com: 31509 vdb-entryx_transferred
- jvndb.jvn.jp: JVNDB-2008-000064 third-party-advisoryx_transferred
- jvn.jp: JVN#99916563 third-party-advisoryx_transferred
- exchange.xforce.ibmcloud.com: eccube-multiple-unspecified-xss(45591) vdb-entryx_transferred
- http://www.ec-cube.net/release/detail.php?release_id=193 x_transferred
- secunia.com: 32065 third-party-advisoryx_transferred