PT-2004-3303 · Vp Asp · Vp-Asp Shopping Cart
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2411
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
VP-ASP Shopping Cart versions 4.0 through 5.0
Description:
The issue concerns the CleanseMessage function in shop$db.asp, which does not properly cleanse inputs. This allows remote attackers to conduct cross-site scripting (XSS) attacks without using parameter in "shopdisplayproducts.asp" or the
msg parameter in "shoperror.asp", and possibly other vectors.Recommendations:
For VP-ASP Shopping Cart versions 4.0 through 5.0, consider disabling the CleanseMessage function in shop$db.asp until a proper fix is available, and restrict access to the affected parameters
cat in "shopdisplayproducts.asp" and msg in "shoperror.asp" to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vp-Asp Shopping Cart