Description
Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.
Remediation
References
Related Vulnerabilities
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-14251)
WordPress Plugin Coming Soon Page & Maintenance Mode Cross-Site Request Forgery (1.7.8)
Oracle Database Server Improper Authentication Vulnerability (CVE-2012-3137)
Oracle Database Server CVE-2015-0483 Vulnerability (CVE-2015-0483)