Back
CVE-2004-2173
SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (17)
| Vendor | Product | Version |
|---|---|---|
| early_impact | productcart | 1.5 |
| early_impact | productcart | 1.6b |
| early_impact | productcart | 1.6b001 |
| early_impact | productcart | 1.6b002 |
| early_impact | productcart | 1.6b003 |
| early_impact | productcart | 1.6br |
| early_impact | productcart | 1.6br001 |
| early_impact | productcart | 1.6br003 |
| early_impact | productcart | 1.5002 |
| early_impact | productcart | 1.5003 |
| early_impact | productcart | 1.5003r |
| early_impact | productcart | 1.5004 |
| early_impact | productcart | 1.6002 |
| early_impact | productcart | 1.6003 |
| early_impact | productcart | 2.0 |
| early_impact | productcart | 2.0br000 |
| early_impact | productcart | 2.5 |
GitHub Security Advisory GHSA-95f9-5gc3-8cfv
SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers...
References (20)
- http://archives.neohapsis.com/archives/bugtraq/2004-02/0503.html Exploit
- http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0871.html Exploit
- http://secunia.com/advisories/10898
- http://securitytracker.com/alerts/2004/Feb/1009085.html
- http://www.earlyimpact.com/productcart/support/updates/ReadMe_ProductCart_Security_Patch_013004.txt
- http://www.osvdb.org/3981
- http://www.s-quadra.com/advisories/Adv-20040216.txt Exploit
- http://www.securityfocus.com/archive/1/354288 Exploit
- http://www.securityfocus.com/bid/9669 Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15233
- http://archives.neohapsis.com/archives/bugtraq/2004-02/0503.html Exploit
- http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0871.html Exploit
- http://secunia.com/advisories/10898
- http://securitytracker.com/alerts/2004/Feb/1009085.html
- http://www.earlyimpact.com/productcart/support/updates/ReadMe_ProductCart_Security_Patch_013004.txt
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.96%
Top 21% most likely to be exploited
Threat Score
30.6 / 100
Data Sources
NVD
EPSS
GitHub