Vulnerabilities > CVE-2005-4063 - Cross-Site Scripting vulnerability in NetauctionHelp

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
netauctionhelp
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) L, (2) sort, (3) category, (4) categoryname parameters to search.asp.

Vulnerable Configurations

Part Description Count
Application
Netauctionhelp
1

Exploit-Db

descriptionNetauctionHelp 3.0 Multiple Cross-Site Scripting Vulnerabilities. CVE-2005-4063 . Webapps exploit for asp platform
idEDB-ID:26744
last seen2016-02-03
modified2005-12-06
published2005-12-06
reporterr0t
sourcehttps://www.exploit-db.com/download/26744/
titleNetauctionHelp 3.0 - Multiple Cross-Site Scripting Vulnerabilities