Cross-site scripting (XSS) vulnerability in suche.htm in ShopXS 4.0 allows remote attackers to inject arbitrary web script or HTML via the Suchstring1 (aka search) parameter.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/25715http://pridels0.blogspot.com/2006/04/shopxs-v40-xss-vuln_10.html