Vulnerabilities > Activewebsoftwares > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-12-30 CVE-2009-4464 Cross-Site Scripting vulnerability in Activewebsoftwares Active Business Directory 2.0
Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
4.3
2009-03-02 CVE-2008-6387 Information Exposure vulnerability in Activewebsoftwares Quick Tree View .Net 3.1
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb.
network
low complexity
activewebsoftwares CWE-200
5.0
2009-02-05 CVE-2009-0430 Cross-Site Scripting vulnerability in Activewebsoftwares Active Bids
Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp.
4.3