CVE-2005-4285
MEDIUM 4.3EPSS 1.8%
Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters.
- CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 1.75% chance of exploitation in the next 30 days, 76th percentile
- Published
- 2005-12-16
- Updated
- 2024-08-07