Unrated severityNVD Advisory· Published Jan 4, 2008· Updated Apr 23, 2026
CVE-2007-6646
CVE-2007-6646
Description
Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1, and possibly other versions before 1.1.0, allow remote attackers to inject arbitrary web script or HTML via (1) the return parameter to user/remindPassword, (2) the q parameter to the category script, (3) the return parameter to the order script, or (4) the email parameter to user/remindComplete.
Affected products
1- cpe:2.3:a:integry_systems:livecart:1.0.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- www.hackerscenter.com/archive/view.aspnvdExploit
- www.securityfocus.com/bid/27087nvdExploit
- secunia.com/advisories/28017nvdVendor Advisory
- archives.neohapsis.com/archives/bugtraq/2008-02/0003.htmlnvd
- livecart.com/news/Major-update-LiveCart-1-1-0.8nvd
- osvdb.org/39756nvd
- osvdb.org/39757nvd
- osvdb.org/39758nvd
- securityreason.com/securityalert/3512nvd
- www.securityfocus.com/archive/1/485654/100/0/threadednvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39305nvd
News mentions
0No linked articles in our index yet.