Weakness Name | Source | |
---|---|---|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |
Metrics | Score | Severity | CVSS Vector | Source |
---|---|---|---|---|
V2 | 2.6 | AV:N/AC:H/Au:N/C:N/I:P/A:N | [email protected] |
Zen-cart>>Zen_cart >> Version *
Zen-cart>>Zen_cart >> Version To (including) 1.5
Zen-cart>>Zen_cart >> Version 1.1.0
Zen-cart>>Zen_cart >> Version 1.1.3
Zen-cart>>Zen_cart >> Version 1.2.0d
Zen-cart>>Zen_cart >> Version 1.2.1
Zen-cart>>Zen_cart >> Version 1.2.1_patch1
Zen-cart>>Zen_cart >> Version 1.2.1d
Zen-cart>>Zen_cart >> Version 1.2.2d
Zen-cart>>Zen_cart >> Version 1.2.3d
Zen-cart>>Zen_cart >> Version 1.2.4.1
Zen-cart>>Zen_cart >> Version 1.2.4d
Zen-cart>>Zen_cart >> Version 1.2.5d
Zen-cart>>Zen_cart >> Version 1.2.6d
Zen-cart>>Zen_cart >> Version 1.3
Zen-cart>>Zen_cart >> Version 1.3.0.2
Zen-cart>>Zen_cart >> Version 1.3.2
Zen-cart>>Zen_cart >> Version 1.3.5
Zen-cart>>Zen_cart >> Version 1.3.6
Zen-cart>>Zen_cart >> Version 1.3.7
Zen-cart>>Zen_cart >> Version 1.3.8
Zen-cart>>Zen_cart >> Version 1.3.8a
Zen-cart>>Zen_cart >> Version 1.3.9
Zen-cart>>Zen_cart >> Version 1.3.9h
Zen-cart>>Zen_cart >> Version 2008