Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2002-06-11T04:00:00
Updated: 2024-08-08T02:49:28.478Z
Reserved: 2002-06-07T00:00:00
Link: CVE-2002-0439

No data.

Status : Deferred
Published: 2002-07-26T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2002-0439

No data.