CVE-2012-6430

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows attackers to inject malicious scripts into the admin page of Quick.Cms and Quick.Cart, potentially compromising the site and its users. It affects versions downloaded before December 19, 2012, and requires the attacker to manipulate the URL to exploit the flaw.

Technical Description

Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin.php. NOTE: this might be a duplicate of CVE-2008-4140.

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$552($500-$1K)
Vendor Response
Grade FPatched in 4375 days

Quick Information

Published

Mar 24, 2014

about 12 years ago

Last Modified

Mar 16, 2026

22 days ago

Vendor

opensolution

Product

quick.cart