HIO-2008-0228-2 Interspire Shopping Cart XSS

Interspire Shopping Cart contains a flaw that allows a remote cross site scripting attack.  This flaw exists because the application does not validate the "search_query" variable upon submission to the search.php script.  This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.

References:

BID: 28029

CVE-2008-1076

OSVDB: 42292

Secunia: 29150

SecWatch  

XF: 40906  

Vendor Solution: Upgrade to latest version

Additional information