Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2002-06-11T04:00:00

Updated: 2024-08-08T02:49:28.478Z

Reserved: 2002-06-07T00:00:00

Link: CVE-2002-0439

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2002-07-26T04:00:00.000

Modified: 2008-09-05T20:28:01.837

Link: CVE-2002-0439

cve-icon Redhat

No data.