Vulnerabilities > CVE-2005-4003 - Cross-Site Scripting vulnerability in Absolute Shopping Package Solutions Shopping Cart 2.1/2.9D

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
asps
exploit available

Summary

Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp. NOTE: the original disclosure was specifically only for an XSS issue, but the CVE description was for SQL injection. Since the original disclosure, SQL injection vectors have been reported. This CVE might be REJECTed or significantly altered pending additional information.

Vulnerable Configurations

Part Description Count
Application
Asps
2

Exploit-Db

  • descriptionASPS Shopping Cart Lite 2.1/Professional 2.9 d bsearch.asp b_search Parameter XSS. CVE-2005-4003 . Webapps exploit for asp platform
    idEDB-ID:26702
    last seen2016-02-03
    modified2005-12-03
    published2005-12-03
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26702/
    titleASPS Shopping Cart Lite 2.1/Professional 2.9 d bsearch.asp b_search Parameter XSS
  • descriptionASPS Shopping Cart Lite 2.1/Professional 2.9 d adv_search.asp srch_product_name Parameter XSS. CVE-2005-4003. Webapps exploit for asp platform
    idEDB-ID:26701
    last seen2016-02-03
    modified2005-12-03
    published2005-12-03
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26701/
    titleASPS Shopping Cart Lite 2.1/Professional 2.9 d adv_search.asp srch_product_name Parameter XSS