CVE-2005-4290
ECW-Cart < 2.03 - Cross-Site Scripting via kword, max, min, comp, or f Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4290. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in ECW-Cart by injecting arbitrary script code via unsanitized user input in the 'kword', 'f', 'min', 'max', and 'comp' parameters. The PoC includes URLs that trigger JavaScript alerts, confirming the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in ECW-Cart by injecting arbitrary script code via unsanitized user input in the 'kword', 'f', 'min', 'max', and 'comp' parameters. The PoC includes URLs that trigger JavaScript alerts, confirming the vulnerability.