High severity7.5NVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2172
CVE-2004-2172
Description
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- archives.neohapsis.com/archives/bugtraq/2004-02/0503.htmlnvdBroken LinkPatchVendor Advisory
- www.s-quadra.com/advisories/Adv-20040216.txtnvdBroken LinkPatchVendor Advisory
- www.securityfocus.com/bid/9669nvdBroken LinkPatchThird Party AdvisoryVDB Entry
- www.earlyimpact.com/productcart/support/updates/ReadMe_ProductCart_Security_Patch_013004.txtnvdExploitThird Party Advisory
- archives.neohapsis.com/archives/fulldisclosure/2004-02/0871.htmlnvdBroken LinkVendor Advisory
- securitytracker.com/alerts/2004/Feb/1009085.htmlnvdBroken LinkThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/354288nvdBroken LinkThird Party AdvisoryVDB EntryVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/15231nvdThird Party AdvisoryVDB Entry
- secunia.com/advisories/10898nvdBroken Link
- www.osvdb.org/3979nvdBroken Link
News mentions
0No linked articles in our index yet.