Unrated severityNVD Advisory· Published Apr 26, 2010· Updated Apr 29, 2026
CVE-2010-1541
CVE-2010-1541
Description
Multiple cross-site scripting (XSS) vulnerabilities in DFD Cart 1.198, 1.197, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category and (2) list_quantity parameters to index.php, and the (3) category parameter to your.order.php.
Affected products
12cpe:2.3:a:dragonfrugal:dfd_cart:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:dragonfrugal:dfd_cart:*:*:*:*:*:*:*:*range: <=1.198
- cpe:2.3:a:dragonfrugal:dfd_cart:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.192:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.193:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.194:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.195:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.196:*:*:*:*:*:*:*
- cpe:2.3:a:dragonfrugal:dfd_cart:1.197:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.