Back

CVE-2005-4288

Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287.

Published: Dec 16, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
marmaraweb marmaraweb_e-commerce *

GitHub Security Advisory GHSA-xrgc-r968-f934

Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 1.93%

Top 22% most likely to be exploited

Threat Score 17.8 / 100

Data Sources

NVD EPSS GitHub