{ "schema_version": "1.4.0", "id": "GHSA-79wr-q3mh-hggx", "modified": "2022-05-02T06:21:35Z", "published": "2022-05-02T06:21:35Z", "aliases": [ "CVE-2010-1328" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tipo or (2) destino parameter to login_registrese.php3 in the Services section, (3) the rubro parameter to precios.php3 in the Products section, (4) the arti parameter to recomenda_articulo.php3 in the Products section, (5) the descrip parameter in a profile action to control/abm_det.php3 in the e-Commerce section, (6) the tit parameter in a delivery_courier action to control/abm_list.php3 in the e-Commerce section, or (7) the tit parameter in an usuario action to control/abm_det.php3 in the e-Commerce section.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-1328" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/59951" }, { "type": "WEB", "url": "http://www.bonsai-sec.com/en/research/vulnerabilities/tornadostore-multiple-xss-0107.php" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/41233" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2010-07-06T17:17:00Z" } }