CVE-2004-2172

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
31/12/2004
Last modified:
03/04/2025

Description

EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netsourcecommerce:productcart:*:*:*:*:*:*:*:* 2.53 (excluding)