Summary
Axis Commerce is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie- based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Axis Commerce versions 0.8.1 and prior are vulnerable.
References
Severity
Classification
-
CVSS Base Score: 2.6
AV:N/AC:H/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Firefox Information Disclosure Vulnerability Jan09 (Linux)
- MediaWiki 'profileinfo.php' Cross Site Scripting Vulnerability
- Alpha Networks ADSL2/2+ Wireless Router version ASL-26555 Password Information Disclosure Vulnerability
- Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
- NewsPortal 'post.php' Cross Site Scripting Vulnerability