Multiple cross-site scripting (XSS) vulnerabilities in search.asp in rwAuction Pro 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) show, (3) searchtype, (4) catid, and (5) searchtxt parameters, a different version and vectors than CVE-2005-4060.
References
Configurations
Information
Published : 2007-07-03 13:30
Updated : 2011-03-07 18:56
NVD link : CVE-2007-3540
Mitre link : CVE-2007-3540
JSON object : View
CWE
Products Affected
rainworx
- rwauction_pro