Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php. NOTE: the vendor was not able to reproduce some of the reported vectors but believes that they have been addressed. The original researcher is known to be unreliable.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2005-05-11T04:00:00
Updated: 2024-08-07T21:51:50.144Z
Reserved: 2005-05-11T00:00:00
Link: CVE-2005-1486

No data.

Status : Modified
Published: 2005-05-11T04:00:00.000
Modified: 2024-11-20T23:57:27.280
Link: CVE-2005-1486

No data.