CVE-2004-2411

Publication date

2005-08-18 04:00:00

Family

mitre

State

PUBLISHED

Description

The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site scripting (XSS) attacks that do not use