| ID | CVE-2011-0504 | ||||||
| Sažetak | Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6, 1.6.1, and probably earlier versions llow remote attackers to inject arbitrary web script or HTML via the (1) status parameter to admin/orders.php, (2) search parameter to admin/customers.php, or (3) STORE_NAME parameter to admin/configuration.php. | ||||||
| Reference | 
 | ||||||
| CVSS | 
 | ||||||
| Pristup | 
 | ||||||
| Impact | 
 | ||||||
| CVSS vektor | AV:N/AC:M/Au:N/C:N/I:P/A:N | ||||||
| Zadnje važnije ažuriranje | 09-10-2018 - 19:29 | ||||||
| Objavljeno | 20-01-2011 - 19:00 | 

