Multiple Cross-Site Scripting Vulnerabilities in Active Auction House by Dujon Digital
CVE-2005-1030
Currently unrated
What is CVE-2005-1030?
Active Auction House has several cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML into the application. The exploitation can occur through various parameters such as ReturnURL, username, and password, targeting multiple endpoints including account.asp and sendpassword.asp. This can lead to session hijacking, data theft, or other malicious activities against users of the platform.
