Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5,...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter in forum.php, which is not properly handled in block_forum_topics.php, and (2) item_id parameter in reviews.php, which is not properly handled in block_reviews.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2979
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/18369
- http://www.attrition.org/pipermail/vim/2006-June/000846.html
- http://www.securityfocus.com/archive/1/436415/100/0/threaded
- http://www.codetosell.com/downloads/xss_fix.zip
- http://www.vupen.com/english/advisories/2006/2253
- http://securityreason.com/securityalert/1087
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27112
- http://secunia.com/advisories/20538
More from viart
View All →Affected Vendor
viart
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.