CVE-2003-1219: XSS
Cross-site scripting (XSS) vulnerability in the tephreflink function in htmloutput.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1219?
CVE-2003-1219 is classified as a medium severity vulnerability due to its exploitation potential allowing XSS attacks.
How do I fix CVE-2003-1219?
To fix CVE-2003-1219, you should upgrade your osCommerce installation to version 2.2-MS3 or later.
What does CVE-2003-1219 affect?
CVE-2003-1219 affects osCommerce versions prior to 2.2-MS3, specifically related to the tep_href_link function in html_output.php.
What type of attack is facilitated by CVE-2003-1219?
CVE-2003-1219 facilitates Cross-Site Scripting (XSS) attacks, allowing remote attackers to inject arbitrary web scripts.
Can CVE-2003-1219 be exploited remotely?
Yes, CVE-2003-1219 can be exploited remotely by attackers through manipulation of the osCsid parameter.