PrestaShop CVE-2008-6503 vulnerability

Core

Score

4.3 Medium

Date publish

20-03-2009

Versiones afectadas

  • Versions from 1.1.0.3 up to and including 1.1.0.3

Description

Multiple cross-site scripting (XSS) vulnerabilities in PrestaShop 1.1.0.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/login.php and (2) order.php.

References

Metrics

cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:M/Au:N/C:N/I:P/A:N
baseScore4.3
accessVectorNETWORK
accessComplexityMEDIUM
authenticationNONE
confidentialityImpactNONE
integrityImpactPARTIAL
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore8.6
impactScore2.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredTrue
Scroll al inicio