Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-12-16T11:00:00
Updated: 2024-08-07T23:38:51.460Z
Reserved: 2005-12-16T00:00:00
Link: CVE-2005-4290
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-12-16T11:03:00.000
Modified: 2024-11-21T00:03:53.853
Link: CVE-2005-4290
Redhat
No data.