CVE-2011-4547: XSS
Multiple cross-site scripting (XSS) vulnerabilities in includes/templates/templatedefault/common/tplheadertestinfo.php in Zen Cart 1.3.9h, when debugging is enabled, might allow remote attackers to inject arbitrary web script or HTML via the (1) mainpage parameter or (2) PATHINFO, a different vulnerability than CVE-2011-4567.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4547?
CVE-2011-4547 is classified as a medium-severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2011-4547?
To fix CVE-2011-4547, it is recommended to upgrade Zen Cart to a version newer than 1.3.9h that addresses this XSS vulnerability.
What types of vulnerabilities are associated with CVE-2011-4547?
CVE-2011-4547 is associated with multiple cross-site scripting (XSS) vulnerabilities that can allow the injection of arbitrary web scripts.
Which versions of Zen Cart are affected by CVE-2011-4547?
CVE-2011-4547 affects Zen Cart version 1.3.9h when debugging is enabled.
Can CVE-2011-4547 be exploited remotely?
Yes, CVE-2011-4547 can be exploited remotely by attackers to execute arbitrary scripts in the context of the affected user's session.