Vulnerabilities > Activewebsoftwares > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-12-30 | CVE-2009-4464 | Cross-Site Scripting vulnerability in Activewebsoftwares Active Business Directory 2.0 Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | 4.3 |
2009-03-02 | CVE-2008-6387 | Information Exposure vulnerability in Activewebsoftwares Quick Tree View .Net 3.1 Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb. | 5.0 |
2009-02-05 | CVE-2009-0430 | Cross-Site Scripting vulnerability in Activewebsoftwares Active Bids Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp. | 4.3 |