about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Active Auction House WatchThisItem.ASP Cross-Site Scripting Vulnerability


Title Active Auction House WatchThisItem.ASP Cross-Site Scripting Vulnerability
Published 2005-04-06-12:00AM
Updated 2005-04-06-06:46PM
Class Input Validation Error
CVE   CAN-2005-1030
Remote  Yes
Local  No
Credit  Discovery of this vulnerability is credited to dcrab <dcrab@hackerscenter.com>.
Vulnerable  Active Web Softwares Active Auction House
Not Vulnerable  
Code   No exploit is required.

The following proof of concept is available:
http://www.example.com/activeauctionsuperstore/watchthisitem.asp?itemid=">&lt;script&gt;alert(document.cookie)&lt;/script&gt;&amp%3baccountid=
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 04 Dec 2008 16:24:15 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
/search/ex NEW.AND.TO Three days CMS is Fre fedora cor 18927 t258t t258t t771t www.qq1331 CMS is Fre puppy php center WCWW.HOTSE Banglisex sex+kurdis Crirtina a tamil sex free porn Sakeela se Waptrix se 18927 AYU ASHARI tamil sex PHP 5 Subs t258t /search/ex CMS+is+Fre news for C t844t t786t joomla com php center newspublis ww w.89.co news for c Real sezx linux 2.6. www.milta. t912t Trisha sex help us up super+vide t999t vBulletin+ www.gadis php nuke d www.gadis+ search/exp WWWSILASEX