First published: Tue Nov 09 2010(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in sample store pages in IBM WebSphere Commerce 7.0 before 7.0.0.1 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2636 is categorized as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2010-2636, upgrade IBM WebSphere Commerce to version 7.0.0.1 or later.
The impacts of CVE-2010-2636 include the ability for remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data.
CVE-2010-2636 affects IBM WebSphere Commerce version 7.0 before 7.0.0.1.
CVE-2010-2636 can be exploited by remote attackers who can craft a specific URL to trigger the vulnerability.