Vulnerabilities > CVE-2004-1844 - Cross-Site Scripting vulnerability in Expinion.net Member Management System

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
expinion-net
exploit available

Summary

Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.

Vulnerable Configurations

Part Description Count
Application
Expinion.Net
1

Exploit-Db

  • descriptionExpinion.net Member Management System 2.1 register.asp err Parameter XSS. CVE-2004-1844. Webapps exploit for asp platform
    idEDB-ID:23854
    last seen2016-02-02
    modified2004-03-20
    published2004-03-20
    reporterManuel Lopez
    sourcehttps://www.exploit-db.com/download/23854/
    titleExpinion.net Member Management System 2.1 register.asp err Parameter XSS
  • descriptionExpinion.net Member Management System 2.1 error.asp err Parameter XSS. CVE-2004-1844. Webapps exploit for asp platform
    idEDB-ID:23853
    last seen2016-02-02
    modified2004-03-20
    published2004-03-20
    reporterManuel Lopez
    sourcehttps://www.exploit-db.com/download/23853/
    titleExpinion.net Member Management System 2.1 error.asp err Parameter XSS