CVE-2004-2123

Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and possibly (3) level parameter of ListCategories.asp.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:nextplace:e-commerce_asp_engine:*:*:*:*:*:*:*:*

Information

Published : 2004-12-30 21:00

Updated : 2017-07-10 18:31


NVD link : CVE-2004-2123

Mitre link : CVE-2004-2123


JSON object : View

Advertisement

dedicated server usa

Products Affected

nextplace

  • e-commerce_asp_engine