Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Clickcartpro | Kryptronic | 1.0 (including) | 1.0 (including) |
Clickcartpro | Kryptronic | 2.0 (including) | 2.0 (including) |
Clickcartpro | Kryptronic | 3.0 (including) | 3.0 (including) |
Clickcartpro | Kryptronic | 3.1 (including) | 3.1 (including) |
Clickcartpro | Kryptronic | 3.2 (including) | 3.2 (including) |
Clickcartpro | Kryptronic | 3.3 (including) | 3.3 (including) |
Clickcartpro | Kryptronic | 3.4 (including) | 3.4 (including) |
Clickcartpro | Kryptronic | 3.5 (including) | 3.5 (including) |
Clickcartpro | Kryptronic | 3.6 (including) | 3.6 (including) |
Clickcartpro | Kryptronic | 4.0 (including) | 4.0 (including) |
Clickcartpro | Kryptronic | 5.0 (including) | 5.0 (including) |
Clickcartpro | Kryptronic | 5.1 (including) | 5.1 (including) |