4.3

CVE-2004-2174

Exploit
Cross-site scripting (XSS) vulnerability in Custva.asp in EarlyImpact ProductCart allows remote attackers to inject arbitrary Javascript via the redirectUrl parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Early ImpactProductcart Version1.5
Early ImpactProductcart Version1.6b
Early ImpactProductcart Version1.6b001
Early ImpactProductcart Version1.6b002
Early ImpactProductcart Version1.6b003
Early ImpactProductcart Version1.6br
Early ImpactProductcart Version1.6br001
Early ImpactProductcart Version1.6br003
Early ImpactProductcart Version1.5002
Early ImpactProductcart Version1.5003
Early ImpactProductcart Version1.5003r
Early ImpactProductcart Version1.5004
Early ImpactProductcart Version1.6002
Early ImpactProductcart Version1.6003
Early ImpactProductcart Version2.0
Early ImpactProductcart Version2.0br000
Early ImpactProductcart Version2.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.757
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2004-02/0503.html
Exploit
http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0871.html
Exploit
http://secunia.com/advisories/10898
http://securitytracker.com/alerts/2004/Feb/1009085.html
http://www.earlyimpact.com/productcart/support/updates/ReadMe_ProductCart_Security_Patch_013004.txt
http://www.s-quadra.com/advisories/Adv-20040216.txt
Exploit
http://www.securityfocus.com/bid/9669
Patch
Exploit
http://www.osvdb.org/3980
https://exchange.xforce.ibmcloud.com/vulnerabilities/15234