ViperSV

3 exploits Active since Sep 2001
CVE-2004-2475 EXPLOITDB text WORKING POC
Google Toolbar 2.0.114.1 - XSS
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.
CVE-2001-0705 EXPLOITDB text WRITEUP
Arcadia Internet Store - Path Traversal
Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.
CVE-2001-0704 EXPLOITDB text WRITEUP
Arcadia Internet Store 1.0 - Path Traversal
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.