Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or HTML via the curPage parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Comersus_cart | Comersus_open_technologies | 3.90 (including) | 3.90 (including) |
Comersus_cart | Comersus_open_technologies | 4.00 (including) | 4.00 (including) |
Comersus_cart | Comersus_open_technologies | 4.14 (including) | 4.14 (including) |
Comersus_cart | Comersus_open_technologies | 4.20b (including) | 4.20b (including) |
Comersus_cart | Comersus_open_technologies | 4.23 (including) | 4.23 (including) |
Comersus_cart | Comersus_open_technologies | 4.27 (including) | 4.27 (including) |
Comersus_cart | Comersus_open_technologies | 4.28 (including) | 4.28 (including) |
Comersus_cart | Comersus_open_technologies | 4.29 (including) | 4.29 (including) |
Comersus_cart | Comersus_open_technologies | 4.36 (including) | 4.36 (including) |
Comersus_cart | Comersus_open_technologies | 4.47 (including) | 4.47 (including) |
Comersus_cart | Comersus_open_technologies | 4.051 (including) | 4.051 (including) |