CVE-2009-0430
Active Bids - Cross-Site Scripting via Search Parameter or URL Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0430. PoCs published by Pouya_Server.
AI-analyzed exploit summary The exploit demonstrates SQL injection and cross-site scripting (XSS) vulnerabilities in Active Auction House and Active Auction Pro. It provides example URLs that can be used to exploit these vulnerabilities by injecting malicious scripts or meta tags.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp.
Exploits (1)
The exploit demonstrates SQL injection and cross-site scripting (XSS) vulnerabilities in Active Auction House and Active Auction Pro. It provides example URLs that can be used to exploit these vulnerabilities by injecting malicious scripts or meta tags.