Multiple Cross-Site Scripting Vulnerabilities in Active Auction House by Dujon Digital
CVE-2005-1030

Currently unrated

Key Information:

Vendor
CVE Published:
2 May 2005

What is CVE-2005-1030?

Active Auction House has several cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML into the application. The exploitation can occur through various parameters such as ReturnURL, username, and password, targeting multiple endpoints including account.asp and sendpassword.asp. This can lead to session hijacking, data theft, or other malicious activities against users of the platform.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.