VendorsEarly Impactproductcart2.0
Vulnerabilities

Early Impact Productcart 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2004-2173
SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter.
Published 2005-07-10 · Modified
7.5EPSS 0.020
CVE-2003-1304
EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information via a direct request.
Published 2006-07-13 · Modified
5.01 PoCEPSS 0.074
CVE-2004-2174
Cross-site scripting (XSS) vulnerability in Custva.asp in EarlyImpact ProductCart allows remote attackers to inject arbitrary Javascript via the redirectUrl parameter.
Published 2005-07-10 · Modified
4.3EPSS 0.018