Unrated severityNVD Advisory· Published Aug 12, 2009· Updated Apr 23, 2026
CVE-2008-6945
CVE-2008-6945
Description
Multiple cross-site scripting (XSS) vulnerabilities in Interchange 5.7 before 5.7.1, 5.6 before 5.6.1, and 5.4 before 5.4.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mv_order_item CGI variable parameter in Core, (2) the country-select widget, or (3) possibly the value specifier when used in the UserTag feature.
Affected products
5cpe:2.3:a:icdevgroup:interchange:5.4.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:icdevgroup:interchange:5.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:icdevgroup:interchange:5.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:icdevgroup:interchange:5.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:icdevgroup:interchange:5.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:icdevgroup:interchange:5.7.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.icdevgroup.org/i/dev/newsnvdPatchVendor Advisory
- ftp.icdevgroup.org/interchange/5.7/WHATSNEWnvdVendor Advisory
- secunia.com/advisories/32658nvdVendor Advisory
- osvdb.org/49852nvd
- osvdb.org/49853nvd
- www.securityfocus.com/bid/32297nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/46598nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/46599nvd
News mentions
0No linked articles in our index yet.