Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2005-0995

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ProductCart 2.7中存在多个跨站脚本攻击(XSS)漏洞,允许远程攻击者通过(1)advSearch_h.asp的keyword参数,(2)NewCust.asp的redirectUrl参数,(3)storelocator_submit.asp的country参数或(4)techErr.asp的error参数来注入任意的Web脚本或HTML。注:已报告ProductCart中并不存在storelocator_submit.asp。

AI Predicted 6.1 Difficulty: Easy EPSS 1.43% · P71
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2005-0995

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to techErr.asp. NOTE: it has been reported that storelocator_submit.asp does not exist in ProductCart.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
ProductCart 跨站脚本攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ProductCart 2.7中存在多个跨站脚本攻击(XSS)漏洞,允许远程攻击者通过(1)advSearch_h.asp的keyword参数,(2)NewCust.asp的redirectUrl参数,(3)storelocator_submit.asp的country参数或(4)techErr.asp的error参数来注入任意的Web脚本或HTML。注:已报告ProductCart中并不存在storelocator_submit.asp。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2005-0995

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-0995

登录查看更多情报信息。

Vendor Advisories for CVE-2005-0995 (5)

Same Patch Batch · n/a · 2005-04-07 · 16 CVEs total

CVE-2005-0992 PHPMyAdmin Convcharset 跨站脚本漏洞
CVE-2005-0993 SCO OpenServer NWPrint缓冲区溢出漏洞
CVE-2005-0994 ProductCart 安全漏洞
CVE-2005-0996 PHP-Nuke Downloads SQL注入漏洞
CVE-2005-0997 PHP-Nuke Web_Links多个SQL注入漏洞
CVE-2005-0998 PHP-Nuke漏洞
CVE-2005-0999 PHP-Nuke Top SQL注入漏洞
CVE-2005-1000 PHP-Nuke Your_Account用户名跨站脚本攻击漏洞
CVE-2005-1001 PHP-Nuke漏洞
CVE-2005-1002 Logics Software LOG-FT远程文件泄露漏洞
CVE-2005-1003 ProfitCode PayProCart 目录遍历漏洞
CVE-2005-1004 ProfitCode Software PayProCart Usrdetails.PHP跨站脚本攻击漏洞
CVE-2005-1005 ProfitCode目录遍历漏洞
CVE-2005-1006 SonicWALL SOHO Web远程输入验证错误漏洞
CVE-2005-1007 CommuniGate Pro LIST未明拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2005-0995

No comments yet


Leave a comment