Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-0681

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2004-0681
Last Modified 05 Sep 2008 04:39:05
Published 06 Aug 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2004-0681

Summary

Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in Comersus Cart 5.09 allow remote attackers to execute web script as other users via the message parameter.

Vulnerable Systems

Application

  • Comersus Open Technologies Comersus Cart 5.09


References

BID - 10674

XF - comersus-cart-xss(16646)

BUGTRAQ - 20040707 Comersus Cart Cross-Site Scripting Vulnerability


Last Updated: 27 May 2016 10:38:42