CVE-2008-6503
Multiple cross-site scripting (XSS) vulnerabilities in PrestaShop 1.1.0.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/login.php and (2) order.php.
- Affected products
- Prestashop
- Prestashop
- = 1.1.0.3
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.5% (73th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2009-03-20
CVE-2008-6503 at NVD
2 known exploits for CVE-2008-6503
Proof-of-concept code and exploit modules indexed by Sploitus