Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2004-2173
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter.
0
Attacker Value
Unknown
CVE-2004-2174
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Custva.asp in EarlyImpact ProductCart allows remote attackers to inject arbitrary Javascript via the redirectUrl parameter.
0
Attacker Value
Unknown
CVE-2003-1304
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information via a direct request.
0
Attacker Value
Unknown
CVE-2003-0523
Disclosure Date: August 18, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.
0
Attacker Value
Unknown
CVE-2003-0522
Disclosure Date: August 18, 2003 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.
0