Vulnerabilities > CVE-2006-0974 - Cross-Site Scripting vulnerability in Battleaxe Software Bttlxeforum 2.0

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
battleaxe-software
exploit available

Summary

Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter. This vulnerability affects Battleaxe Software, bttlxeForum versions 2.0 and previous

Vulnerable Configurations

Part Description Count
Application
Battleaxe_Software
1

Exploit-Db

descriptionBattleaxe Software BttlxeForum 2.0 Failure.ASP Cross-Site Scripting Vulnerability. CVE-2006-0974. Webapps exploit for asp platform
idEDB-ID:27310
last seen2016-02-03
modified2006-02-25
published2006-02-25
reporterrUnViRuS
sourcehttps://www.exploit-db.com/download/27310/
titleBattleaxe Software BttlxeForum 2.0 Failure.ASP Cross-Site Scripting Vulnerability