CVE-2005-4003

ASPS Shopping Cart Professional <= 2.9d and Lite <= 2.1 - SQL Injection via srch_product_name or b_search Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-4003. PoCs published by r0t3d3Vil.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in ASPS Shopping Cart by injecting a script tag into the 'b_search' parameter. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.

Description

Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp. NOTE: the original disclosure was specifically only for an XSS issue, but the CVE description was for SQL injection. Since the original disclosure, SQL injection vectors have been reported. This CVE might be REJECTed or significantly altered pending additional information.

Exploits (2)

exploitdb WORKING POC VERIFIED
by r0t3d3Vil · textwebappsasp
https://www.exploit-db.com/exploits/26702

This exploit demonstrates a cross-site scripting (XSS) vulnerability in ASPS Shopping Cart by injecting a script tag into the 'b_search' parameter. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: ASPS Shopping Cart
No auth needed
Prerequisites: A vulnerable version of ASPS Shopping Cart · User interaction to trigger the XSS payload
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by r0t3d3Vil · textwebappsasp
https://www.exploit-db.com/exploits/26701

This exploit demonstrates a cross-site scripting (XSS) vulnerability in ASPS Shopping Cart by injecting a script tag into the search parameters. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: ASPS Shopping Cart
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15694

Scores

EPSS 0.0105
EPSS Percentile 59.8%

Details

Status published
Products (2)
asps/shopping_cart 2.1
asps/shopping_cart 2.9d
Published Dec 05, 2005
Tracked Since Feb 18, 2026