CVE-2015-3300
TheCartPress eCommerce Shopping Cart(일명 The Professional WordPress eCommerce Plugin) WordPress 플러그인 1.3.9.3 이전 버전에는 다중 XSS(크로스 사이트 스크립팅) 취약점이 존재하며, 원격 공격자는...
- 게시됨
- 2015. 5. 14.
- 업데이트됨
- 2024. 8. 6.
- CNA 할당 중
- mitre
- 증거 관찰됨
- 2015. 4. 29.
기본 CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N낮음 · 다음 30일
- 백분위수
- 93.4%
- 모델 날짜
- 2026. 9. 21.
EPSS는 통계적 추정치이지 확실성이나 영향의 척도가 아닙니다. 이를 CVSS, KEV 상태, 노출 및 환경과 결합하세요.
요약
TheCartPress eCommerce Shopping Cart(일명 The Professional WordPress eCommerce Plugin) WordPress 플러그인 1.3.9.3 이전 버전에는 다중 XSS(크로스 사이트 스크립팅) 취약점이 존재하며, 원격 공격자는 shopping-cart/checkout/ 경로로 전달되는 (1) billing_firstname, (2) billing_lastname, (3) billing_company, (4) billing_tax_id_number, (5) billing_city, (6) billing_street, (7) billing_street_2, (8) billing_postcode, (9) billing_telephone_1, (10) billing_telephone_2, (11) billing_fax, (12) shipping_firstname, (13) shipping_lastname, (14) shipping_company, (15) shipping_tax_id_number, (16) shipping_city, (17) shipping_street, (18) shipping_street_2, (19) shipping_postcode, (20) shipping_telephone_1, (21) shipping_telephone_2, (22) shipping_fax 매개변수; wp-admin/admin.php의 admin/AddressesList.php 페이지에 있는 (23) search_by 매개변수; wp-admin/admin.php의 admin/AddressEdit.php 페이지에 있는 (24) address_id, (25) address_name, (26) firstname, (27) lastname, (28) street, (29) city, (30) postcode, (31) email 매개변수; wp-admin/admin.php의 admin/AssignedCategoriesList.php 페이지에 있는 (32) post_id 또는 (33) rel_type 매개변수; 또는 wp-admin/admin.php의 admin/CustomFieldsList.php 페이지에 있는 (34) post_type 매개변수를 통해 임의의 웹 스크립트 또는 HTML을 주입할 수 있습니다.
소스
1High-Tech Bridge SA · php · 2015. 4. 29.
책임 있는 사용
귀하가 소유하고 있거나 테스트할 권한이 있는 시스템에 대해서만 취약점 정보를 사용하십시오. Kitploit은 공개 연구 메타데이터에 연결되며 익스플로잇 코드나 악성 페이로드를 저장하지 않습니다.