CVE-2005-1030

Active Auction House - Stored Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2005-1030. PoCs published by Dcrab.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Active Auction House by injecting a script tag into the 'itemid' parameter of the 'watchthisitem.asp' page. The script executes arbitrary JavaScript, potentially stealing cookies or performing other malicious actions in the context of the user's session.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to watchthisitem.asp.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Dcrab · textwebappsasp
https://www.exploit-db.com/exploits/25352

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Active Auction House by injecting a script tag into the 'itemid' parameter of the 'watchthisitem.asp' page. The script executes arbitrary JavaScript, potentially stealing cookies or performing other malicious actions in the context of the user's session.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Active Auction House (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable web application · User interaction to trigger the XSS payload
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Dcrab · textwebappsasp
https://www.exploit-db.com/exploits/25348

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Active Auction House by injecting arbitrary script code via unsanitized user input in the username and password parameters.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Active Auction House (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Dcrab · textwebappsasp
https://www.exploit-db.com/exploits/25351

This exploit demonstrates cross-site scripting (XSS) vulnerabilities in Active Auction House by injecting arbitrary script code via unsanitized input parameters in the sendpassword.asp page. The PoC uses script tags to execute JavaScript in the context of a user's browser.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Active Auction House (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Dcrab · textwebappsasp
https://www.exploit-db.com/exploits/25349

The provided text describes a cross-site scripting (XSS) vulnerability in Active Auction House, where user-supplied input is not properly sanitized. The example URL demonstrates how arbitrary script code can be executed in a user's browser.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Active Auction House
No auth needed
Prerequisites: Access to the vulnerable application URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15287
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13038
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15286
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13036
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13039
Exploit vdb-entry x_refsource_sectrack
http://www.securitytracker.com/alerts/2005/Apr/1013649.html
Various Sources x_refsource_misc
http://digitalparadox.org/advisories/aass.txt
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111280834000432&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15284
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15285
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19975
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14839

Scores

EPSS 0.0509
EPSS Percentile 91.3%

Details

Status published
Products (1)
active_web_softwares/active_auction_house 7.1
Published May 02, 2005
Tracked Since Feb 18, 2026