6.8
CVSSv2

CVE-2003-0523

Published: 18/08/2003 Updated: 18/10/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote malicious users to execute arbitrary web script via the message parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

early impact productcart 1.5003

early impact productcart 1.5003r

early impact productcart 1.6b003

early impact productcart 1.6br

early impact productcart 1.5004

early impact productcart 1.6002

early impact productcart 1.6br001

early impact productcart 1.6br003

early impact productcart 1.6003

early impact productcart 1.6b

early impact productcart 2

early impact productcart 2br000

early impact productcart 1.5

early impact productcart 1.5002

early impact productcart 1.6b001

early impact productcart 1.6b002

Exploits

source: wwwsecurityfocuscom/bid/8108/info A cross-site scripting vulnerability has been reported for ProductCart The vulnerability exists due to insufficient sanitization of some user-supplied values Exploitation could permit an attacker to steal cookie-based authentication credentials or launch other attacks wwwwebsitecom/P ...