# Exploit Title: X-Cart Cross Site Scripting # Date: 30/06/2015 # Exploit Author: nopesled # Vendor Homepage: http://www.x-cart.com/ # Version: 4.5.0 and possibly earlier Details ------- Websites running X-Cart version 4.5.0 (and possibly below) which have not removed their /install/ directory are vulnerable to Cross Site Scripting via a GET request. The affected code is as follows: