Comersus ASP Shopping Cart suffers from cross site scripting and database disclosure vulnerabilities.