Unrated severityNVD Advisory· Published May 2, 2005· Updated Apr 16, 2026
CVE-2005-0995
CVE-2005-0995
Description
Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to techErr.asp. NOTE: it has been reported that storelocator_submit.asp does not exist in ProductCart.
Affected products
1- cpe:2.3:a:early_impact:productcart:2.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.osvdb.org/15264nvdExploit
- www.osvdb.org/15266nvdExploit
- www.osvdb.org/15268nvdExploit
- www.securityfocus.com/bid/12990nvdExploit
- secunia.com/advisories/14833nvdVendor Advisory
- digitalparadox.org/advisories/prodcart.txtnvd
- www.osvdb.org/15267nvd
News mentions
0No linked articles in our index yet.