Record summary

CVE-2004-0681 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in Comersus Cart 5.09 allow remote attackers to execute web script as other users via the message parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBComersus Open Technologies Comersus 5.0 - 'comersus_message.asp' Cross-Site ScriptingExploitDB exploitby Thomas RyanNot analyzed1 file
ExploitDB

PoC details

References

4