CVE

Id
14940  
CVE No.
CVE-2005-3736  
Status
Candidate  
Description
Multiple cross-site scripting (XSS) vulnerabilities in e-Quick Cart allow remote attackers to inject arbitrary web script or HTML via the (1) strgifttoname parameter in shopgift.asp, (2) strfirstname parameter in shopmaillist.asp, (3) strpid parameter in shopprojectlogin.asp, and (4) Custname parameter in shoptellafriend.asp.  
Phase
Assigned (20051121)  
Votes
None (candidate not yet proposed)  
Comments