CVE-2005-0995
Last modified
CVE-2005-0995 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to techErr.asp. NOTE: it has been reported that storelocator_submit.asp does not exist in ProductCart.. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to techErr.asp. NOTE: it has been reported that storelocator_submit.asp does not exist in ProductCart.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Early Impact | Productcart | 2.7 |
References
- http://secunia.com/advisories/14833Vendor Advisory
- http://www.osvdb.org/15264Exploit
- http://www.osvdb.org/15266Exploit
- http://www.osvdb.org/15268Exploit
- http://secunia.com/advisories/14833Vendor Advisory
- http://www.osvdb.org/15264Exploit
- http://www.osvdb.org/15266Exploit
- http://www.osvdb.org/15268Exploit
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0995?
How severe is CVE-2005-0995?
How do I fix CVE-2005-0995?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0989The find_replen function in jsstr.c in the Javascript engine…
- CVE-2005-0990unshar (unshar.c) in sharutils 4.2.1 allows local users to o…
- CVE-2005-0991RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure …
- CVE-2005-0992Cross-site scripting (XSS) vulnerability in index.php in php…
- CVE-2005-0993Buffer overflow in nwprint in SCO OpenServer 5.0.7 allows lo…
- CVE-2005-0994Multiple SQL injection vulnerabilities in ProductCart 2.7 al…
- CVE-2005-0996Multiple SQL injection vulnerabilities in the Downloads modu…
- CVE-2005-0997Multiple SQL injection vulnerabilities in the Web_Links modu…
- CVE-2005-0998The Web_Links module for PHP-Nuke 7.6 allows remote attacker…
- CVE-2005-0999SQL injection vulnerability in the Top module for PHP-Nuke 6…
- CVE-2005-1000Multiple cross-site scripting (XSS) vulnerabilities in PHP-N…
- CVE-2005-10001A vulnerability was found in Netegrity SiteMinder up to 4.5.…6.1
Are you affected by CVE-2005-0995?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
