CVE-2023-36163

Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.
Configurations

Configuration 1 (hide)

cpe:2.3:a:buildagate_project:buildagate:5:*:*:*:*:*:*:*

History

21 Jul 2023, 16:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Buildagate Project buildagate
Buildagate Project
CWE CWE-79
References (MISC) http://www.misdar-jabo.org/BuildaGate5/general2/company_search_tree.php?NewNameMade=0&SiteName=misdar&lan=en&EnterDefault=&Referral=tree&BuyerID=104732450&Clubtmp1=&SearchTop= - (MISC) http://www.misdar-jabo.org/BuildaGate5/general2/company_search_tree.php?NewNameMade=0&SiteName=misdar&lan=en&EnterDefault=&Referral=tree&BuyerID=104732450&Clubtmp1=&SearchTop= - Broken Link
References (MISC) https://afula.libraries.co.il/BuildaGate5library/general2/company_search_tree.php?mc=0 - (MISC) https://afula.libraries.co.il/BuildaGate5library/general2/company_search_tree.php?mc=0 - Broken Link
References (MISC) http://packetstormsecurity.com/files/173366/BuildaGate5-Cross-Site-Scripting.html - (MISC) http://packetstormsecurity.com/files/173366/BuildaGate5-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry
References (MISC) http://www.levi-coins.co.il/BuildaGate5/general2/company_search_tree.php?SiteName=levicoins - (MISC) http://www.levi-coins.co.il/BuildaGate5/general2/company_search_tree.php?SiteName=levicoins - Not Applicable
References (MISC) https://github.com/TraiLeR2?tab=overview&from=2023-05-01&to=2023-05-31 - (MISC) https://github.com/TraiLeR2?tab=overview&from=2023-05-01&to=2023-05-31 - Third Party Advisory
CPE cpe:2.3:a:buildagate_project:buildagate:5:*:*:*:*:*:*:*

11 Jul 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/173366/BuildaGate5-Cross-Site-Scripting.html -

11 Jul 2023, 14:27

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-11 14:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-36163

Mitre link : CVE-2023-36163

CVE.ORG link : CVE-2023-36163


JSON object : View

Products Affected

buildagate_project

  • buildagate
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')