Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cartwiz | Elemental_software | 1.10 (including) | 1.10 (including) |
Cartwiz | Elemental_software | 1.20 (including) | 1.20 (including) |