Vulnerabilities > CVE-2005-4166 - Cross-Site Scripting vulnerability in DuWare DuPortalPro Password.ASP

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
duware
exploit available

Summary

Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter.

Vulnerable Configurations

Part Description Count
Application
Duware
1

Exploit-Db

descriptionDuWare DuPortalPro 3.4.3 Password.ASP Cross-Site Scripting Vulnerability. CVE-2005-4166 . Webapps exploit for asp platform
idEDB-ID:26742
last seen2016-02-03
modified2005-12-06
published2005-12-06
reporterDj_Eyes
sourcehttps://www.exploit-db.com/download/26742/
titleDuWare DuPortalPro 3.4.3 Password.ASP Cross-Site Scripting Vulnerability