← Back

CVE-2010-1486

nvd nist
Published: Apr 22, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or HTML via the (1) billing address or (2) shipping address.

Affected (9)

Products: Cactushop: Cactushop
1 product
Cactushop
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Cactushop
Up to 6.1
Version 3
Version 4.1
Version 4.5
Version 4.6
Version 4.7
Version 4
Version 5.0
Version 5.1

Timeline

No history available yet.