Multiple cross-site scripting (XSS) vulnerabilities in search.asp in rwAuction Pro 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) show, (3) searchtype, (4) catid, and (5) searchtxt parameters, a different version and vectors than CVE-2005-4060.
References
Configurations
History
21 Nov 2024, 00:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/36347 - | |
References | () http://pridels-team.blogspot.com/2007/06/rwauction-pro-xss-vuln.html - | |
References | () http://secunia.com/advisories/25849 - | |
References | () http://www.securityfocus.com/bid/24668 - | |
References | () http://www.vupen.com/english/advisories/2007/2368 - |
Information
Published : 2007-07-03 20:30
Updated : 2024-11-21 00:33
NVD link : CVE-2007-3540
Mitre link : CVE-2007-3540
CVE.ORG link : CVE-2007-3540
JSON object : View
Products Affected
rainworx
- rwauction_pro
CWE