4.3

CVE-2005-1030

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to watchthisitem.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Active Web SoftwaresActive Auction House Version7.1 Editionpro
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.09% 0.913
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://digitalparadox.org/advisories/aass.txt
http://marc.info/?l=bugtraq&m=111280834000432&w=2
http://secunia.com/advisories/14839
Vendor Advisory
Exploit
http://www.securitytracker.com/alerts/2005/Apr/1013649.html
Exploit
http://www.osvdb.org/15284
http://www.osvdb.org/15285
http://www.osvdb.org/15286
http://www.osvdb.org/15287
http://www.securityfocus.com/bid/13036
Exploit
http://www.securityfocus.com/bid/13038
Exploit
http://www.securityfocus.com/bid/13039
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/19975