Vulnerabilities > CVE-2004-0675 - Cross-Site Scripting vulnerability in McMurtrey/Whitaker & Associates Cart32 GetLatestBuilds Script

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
mcmurtrey-whitaker-and-associates
exploit available

Summary

Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command.

Exploit-Db

descriptionMcMurtrey/Whitaker & Associates Cart32 2-5 GetLatestBuilds Script Cross-Site Scripting Vulnerability. CVE-2004-0675 . Webapps exploit for cgi platform
idEDB-ID:24236
last seen2016-02-02
modified2004-06-28
published2004-06-28
reporterDr.Ponidi Haryanto
sourcehttps://www.exploit-db.com/download/24236/
titleMcMurtrey/Whitaker & Associates Cart32 2-5 GetLatestBuilds Script Cross-Site Scripting Vulnerability