VYPR

Ezwaiter Online

by Chamberland Technology

CVEs (1)

  • CVE-2006-3613Jul 18, 2006
    risk 0.00cvss epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in Chamberland Technology ezWaiter 3.0 Online and possibly Enterprise Software (aka enterprise edition) allow remote attackers to inject arbitrary web script or HTML via the (1) itemfor (aka "Who is this item for?") and (2) special (aka "Special Instructions") parameters to item.php, which is accessed from showorder.php, or (3) unspecified parameters to the login form at login.php.