Back
CVE-2003-0523
Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.
Published: Aug 18, 2003
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (16)
| Vendor | Product | Version |
|---|---|---|
| early_impact | productcart | 1.5 |
| early_impact | productcart | 1.6b |
| early_impact | productcart | 1.6b001 |
| early_impact | productcart | 1.6b002 |
| early_impact | productcart | 1.6b003 |
| early_impact | productcart | 1.6br |
| early_impact | productcart | 1.6br001 |
| early_impact | productcart | 1.6br003 |
| early_impact | productcart | 1.5002 |
| early_impact | productcart | 1.5003 |
| early_impact | productcart | 1.5003r |
| early_impact | productcart | 1.5004 |
| early_impact | productcart | 1.6002 |
| early_impact | productcart | 1.6003 |
| early_impact | productcart | 2 |
| early_impact | productcart | 2br000 |
GitHub Security Advisory GHSA-8m7x-wh4h-j28j
Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow...
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
3.30%
Top 13% most likely to be exploited
Threat Score
28.2 / 100
Data Sources
NVD
EPSS
GitHub