CVE-2009-0430

Active Bids - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Pouya_Server · textwebappsasp
https://www.exploit-db.com/exploits/32730

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/500144/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33306

Scores

EPSS 0.0064
EPSS Percentile 70.7%

Details

CWE
CWE-79
Status published
Products (1)
activewebsoftwares/active_bids
Published Feb 05, 2009
Tracked Since Feb 18, 2026