Unrated severityNVD Advisory· Published Apr 5, 2015· Updated May 6, 2026
CVE-2015-0950
CVE-2015-0950
Description
Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter.
Affected products
5cpe:2.3:a:qualiteam:x-cart:5.1.10:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:qualiteam:x-cart:5.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:qualiteam:x-cart:5.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:qualiteam:x-cart:5.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:qualiteam:x-cart:5.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:qualiteam:x-cart:5.1.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- blog.x-cart.com/5-1-11-released.htmlnvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/924124nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.