Vulnerability Details CVE-2010-1541
Multiple cross-site scripting (XSS) vulnerabilities in DFD Cart 1.198, 1.197, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category and (2) list_quantity parameters to index.php, and the (3) category parameter to your.order.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.3%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2010-1541
-
cpe:2.3:a:dragonfrugal:dfd_cart:*
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.1.4
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.1.5
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.1.6
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.1.7
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.1.8
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.192
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.193
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.194
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.195
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.196
-
cpe:2.3:a:dragonfrugal:dfd_cart:1.197