PT-2004-3303 · Vp Asp · Vp-Asp Shopping Cart

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2411

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: VP-ASP Shopping Cart versions 4.0 through 5.0
Description: The issue concerns the CleanseMessage function in shop$db.asp, which does not properly cleanse inputs. This allows remote attackers to conduct cross-site scripting (XSS) attacks without using parameter in "shopdisplayproducts.asp" or the msg parameter in "shoperror.asp", and possibly other vectors.
Recommendations: For VP-ASP Shopping Cart versions 4.0 through 5.0, consider disabling the CleanseMessage function in shop$db.asp until a proper fix is available, and restrict access to the affected parameters cat in "shopdisplayproducts.asp" and msg in "shoperror.asp" to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2411

Affected Products

Vp-Asp Shopping Cart