Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jshop_professional | Jshop_e-commerce | 3.0 (including) | 3.0 (including) |
Jshop_professional | Jshop_e-commerce | 3.1 (including) | 3.1 (including) |
Jshop_professional | Jshop_e-commerce | 3.2 (including) | 3.2 (including) |
Jshop_professional | Jshop_e-commerce | 3.3 (including) | 3.3 (including) |
Jshop_professional | Jshop_e-commerce | 3.4 (including) | 3.4 (including) |
Jshop_server | Jshop_e-commerce | 1.0.1 (including) | 1.0.1 (including) |
Jshop_server | Jshop_e-commerce | 1.0.2 (including) | 1.0.2 (including) |
Jshop_server | Jshop_e-commerce | 1.0.3 (including) | 1.0.3 (including) |
Jshop_server | Jshop_e-commerce | 1.0.4 (including) | 1.0.4 (including) |
Jshop_server | Jshop_e-commerce | 1.1.0 (including) | 1.1.0 (including) |
Jshop_server | Jshop_e-commerce | 1.2.0 (including) | 1.2.0 (including) |