First published: Sun Dec 31 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zen Cart | =1.1.2d | |
Zen Cart | =1.2.6d | |
Zen Cart | =1.2.7 | |
Zen Cart | =1.3 | |
Zen Cart | =1.3.2 | |
Zen Cart | =1.3.5 | |
=1.1.2d | ||
=1.2.6d | ||
=1.2.7 | ||
=1.3 | ||
=1.3.2 | ||
=1.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6868 is considered a medium to high severity vulnerability due to its potential to allow cross-site scripting attacks.
To fix CVE-2006-6868, you should upgrade Zen Cart to version 1.3.7 or later, which addresses these XSS vulnerabilities.
CVE-2006-6868 affects Zen Cart versions prior to 1.3.7, including 1.1.2d, 1.2.6d, 1.2.7, 1.3, 1.3.2, and 1.3.5.
CVE-2006-6868 is classified as a cross-site scripting (XSS) vulnerability that enables remote attackers to inject arbitrary web scripts.
Users of Zen Cart prior to version 1.3.7 are at risk of being affected by CVE-2006-6868 if they do not implement the necessary updates.