header-logo
Suggest Exploit
vendor:
ViArt Shop
by:
SecurityFocus
7.5
CVSS
HIGH
Multiple Cross-Site Scripting, Information Disclosure, Authentication Bypass
79, 200, 287
CWE
Product Name: ViArt Shop
Affected Version From: 3.5
Affected Version To: 3.5
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

ViArt Shop Multiple Remote Vulnerabilities

An attacker can exploit these issues to execute arbitrary script code, steal cookie-based authentication credentials, obtain sensitive information, or gain unauthorized access to the affected application.

Mitigation:

Update to the latest version of ViArt Shop.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/33043/info


ViArt Shop is prone to multiple remote vulnerabilities:

- Multiple cross-site scripting vulnerabilities
- An information-disclosure vulnerability
- An authentication-bypass vulnerability

An attacker can exploit these issues to execute arbitrary script code, steal cookie-based authentication credentials, obtain sensitive information, or gain unauthorized access to the affected application.

ViArt Shop 3.5 is vulnerable; other versions may also be affected.

http://www.example.com/manuals_search.php?manuals_search=<html><script>window.location="http://www.example2.com";</script></html>