CVE-2006-5119: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart 1.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) adminname or (2) adminpass parameter in (a) admin/login.php, or the (3) adminemail parameter in (b) admin/passwordforgotten.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5119?
CVE-2006-5119 is considered a medium severity vulnerability due to its ability to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2006-5119?
To fix CVE-2006-5119, you should upgrade to a newer version of Zen Cart that addresses these vulnerabilities.
What are the affected components of CVE-2006-5119?
CVE-2006-5119 affects the admin/login.php and admin/password_forgotten.php components of Zen Cart 1.3.5.
What types of attacks are possible with CVE-2006-5119?
CVE-2006-5119 allows remote attackers to inject arbitrary web scripts or HTML, leading to potential XSS attacks.
Who is impacted by CVE-2006-5119?
Users of Zen Cart version 1.3.5 are impacted by CVE-2006-5119 due to the presence of XSS vulnerabilities.