Vulnerabilities > CVE-2007-0950 - Input Validation vulnerability in Fullaspsite Shop Listmain.ASP

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
fullaspsite
exploit available

Summary

Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

Vulnerable Configurations

Part Description Count
Application
Fullaspsite
1

Exploit-Db

descriptionFullaspsite ASP Hosting Site listmain.asp cat Parameter XSS. CVE-2007-0950. Webapps exploit for asp platform
idEDB-ID:29600
last seen2016-02-03
modified2007-02-13
published2007-02-13
reporterShaFuck31
sourcehttps://www.exploit-db.com/download/29600/
titleFullaspsite ASP Hosting Site listmain.asp cat Parameter XSS