Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2002-06-11T04:00:00
Updated: 2024-08-08T02:49:28.478Z
Reserved: 2002-06-07T00:00:00
Link: CVE-2002-0439
Vulnrichment
No data.
NVD
Status : Modified
Published: 2002-07-26T04:00:00.000
Modified: 2024-11-20T23:39:05.817
Link: CVE-2002-0439
Redhat
No data.