Early Impact develops a focused e-commerce platform (ProductCart) that, despite a narrow product footprint, occupies a notable position in the vulnerability landscape and attracts public exploit development. The recurring weakness classifications reflect the complexity of payment and customer-data handling in web-facing commerce applications, and defenders should monitor this vendor's release cycles for patches affecting exposed storefronts. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Early Impact over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1304MEDIUM EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive database inf | Dec 31, 2003 | 5.0 | 30 | NO | YES |
CVE-2005-0994HIGH Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or resultCnt parameters to advSearch_h.asp, | May 2, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-1967HIGH Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, | Jun 16, 2005 | 7.5 | 28 | NO | YES |
CVE-2003-0523MEDIUM Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter. | Aug 18, 2003 | 6.8 | 27 | NO | YES |
CVE-2003-0522HIGH Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or ( | Aug 18, 2003 | 10.0 | 25 | NO | NO |
CVE-2004-2173HIGH SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter. | Dec 31, 2004 | 7.5 | 20 | NO | NO |
CVE-2005-2445HIGH SQL injection vulnerability in viewPrd.asp in Product Cart 2.6 allows remote attackers to execute arbitrary SQL commands via the idcategory parameter. | Aug 3, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1968MEDIUM Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp. | Jun 8, 2005 | 4.3 | 14 | NO | NO |
CVE-2005-0995MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.as | May 2, 2005 | 4.3 | 14 | NO | NO |
CVE-2004-2174MEDIUM Cross-site scripting (XSS) vulnerability in Custva.asp in EarlyImpact ProductCart allows remote attackers to inject arbitrary Javascript via the redirectUrl parameter. | Dec 31, 2004 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Early Impact.
Media articles that mention a CVE ID that affects a product developed by Early Impact — matched by CVE ID, not by vendor name.