Vulnerabilities > CVE-2006-0217 - Cross-Site Scripting vulnerability in Ultimate Auction Ultimate Auction 3.67

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
ultimate-auction
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.

Vulnerable Configurations

Part Description Count
Application
Ultimate_Auction
1

Exploit-Db

  • descriptionUltimate Auction 3.67 ItemList.PL Cross-Site Scripting Vulnerability. CVE-2006-0217. Webapps exploit for cgi platform
    idEDB-ID:27091
    last seen2016-02-03
    modified2006-01-16
    published2006-01-16
    reporterquerkopf
    sourcehttps://www.exploit-db.com/download/27091/
    titleUltimate Auction 3.67 ItemList.PL Cross-Site Scripting Vulnerability
  • descriptionUltimate Auction 3.67 Item.PL Cross-Site Scripting Vulnerability. CVE-2006-0217. Webapps exploit for cgi platform
    idEDB-ID:27081
    last seen2016-02-03
    modified2006-01-14
    published2006-01-14
    reporterquerkopf
    sourcehttps://www.exploit-db.com/download/27081/
    titleUltimate Auction 3.67 Item.PL Cross-Site Scripting Vulnerability