Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:25834
HistoryMar 03, 2011 - 12:00 a.m.

Prestashop Cartium 1.3.3 Multiple Cross Site Scripting (XSS)

2011-03-0300:00:00
vulners.com
71

Hello,
In Prestashop Cartium 1.3.3 I have detected multiple Cross Site Scripting (XSS)
vulnerabilities:

File Field
categoty.php id_category
product.php id_product
search.php search_query

Test pattern for vulnerable versions:

"></script>alert(1)</script>

Kind Regards
Antonio San Martino