Vulnerabilities > Elemental Software > Cartwiz

DATE CVE VULNERABILITY TITLE RISK
2005-08-03 CVE-2005-2427 Cross-Site Scripting vulnerability in Elemental Software Cartwiz
Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.
4.3
2005-07-27 CVE-2005-2386 Cross-Site Scripting vulnerability in Elemental Software Cartwiz 1.10/1.20
Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
4.3
2005-07-11 CVE-2005-2207 Cross-Site Scripting vulnerability in CartWIZ
Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.
4.3
2005-07-11 CVE-2005-2206 SQL-Injection vulnerability in CartWIZ
Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.
network
low complexity
elemental-software
7.5
2005-05-02 CVE-2005-1292 Cross-Site Scripting vulnerability in CartWIZ
Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.
4.3