Vulnerabilities > CVE-2005-1004 - Unspecified vulnerability in Profitcode Payprocart 3.0

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
profitcode
nessus
exploit available

Summary

Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML via the sgnuptype parameter.

Vulnerable Configurations

Part Description Count
Application
Profitcode
1

Exploit-Db

descriptionProfitCode Software PayProCart 3.0 Usrdetails.PHP Cross-Site Scripting Vulnerability. CVE-2005-1004. Webapps exploit for php platform
idEDB-ID:25337
last seen2016-02-03
modified2005-04-05
published2005-04-05
reporterDiabolic Crab
sourcehttps://www.exploit-db.com/download/25337/
titleProfitCode Software PayProCart 3.0 Usrdetails.PHP Cross-Site Scripting Vulnerability

Nessus

NASL familyCGI abuses : XSS
NASL idPAYPROCART_XSS.NASL
descriptionThe remote host is running PayProCart, a shopping cart software program written in PHP. The remote version of this software contains an input validation flaw in the file
last seen2020-06-01
modified2020-06-02
plugin id17996
published2005-04-07
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/17996
titleProfitCode PayProCart usrdetails.php sgnuptype Parameter XSS