Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2174
CVE-2004-2174
Description
Cross-site scripting (XSS) vulnerability in Custva.asp in EarlyImpact ProductCart allows remote attackers to inject arbitrary Javascript via the redirectUrl parameter.
Affected products
17cpe:2.3:a:early_impact:productcart:1.5:*:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:early_impact:productcart:1.5:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.5002:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.5003:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.5003r:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.5004:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.6002:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.6003:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.6b:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.6b001:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.6b002:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.6b003:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.6br:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.6br001:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:1.6br003:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:2.0br000:*:*:*:*:*:*:*
- cpe:2.3:a:early_impact:productcart:2.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- archives.neohapsis.com/archives/bugtraq/2004-02/0503.htmlnvdExploit
- archives.neohapsis.com/archives/fulldisclosure/2004-02/0871.htmlnvdExploit
- www.s-quadra.com/advisories/Adv-20040216.txtnvdExploit
- www.securityfocus.com/bid/9669nvdExploitPatch
- secunia.com/advisories/10898nvd
- securitytracker.com/alerts/2004/Feb/1009085.htmlnvd
- www.earlyimpact.com/productcart/support/updates/ReadMe_ProductCart_Security_Patch_013004.txtnvd
- www.osvdb.org/3980nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15234nvd
News mentions
0No linked articles in our index yet.