Vulnerability Name: | CVE-2002-0257 (CCN-8161) | ||||||||
Assigned: | 2002-02-09 | ||||||||
Published: | 2002-02-09 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sat Feb 09 2002 - 11:02:36 CST Account theft vulnerability in MakeBid Auction Deluxe 3.30 Source: MITRE Type: CNA CVE-2002-0257 Source: BUGTRAQ Type: UNKNOWN 20020209 Account theft vulnerability in MakeBid Auction Deluxe 3.30 Source: XF Type: Patch, Vendor Advisory makebid-description-css(8161) Source: CONFIRM Type: UNKNOWN http://www.netcreations.addr.com/dcforum/DCForumID2/126.html Source: CCN Type: USANet Creations Web site Fix/Upgrades Source: CCN Type: OSVDB ID: 9286 MakeBid Auction Deluxe auction.pl Multiple Parameter XSS Source: BID Type: Patch, Vendor Advisory 4069 Source: CCN Type: BID-4069 MakeBid Auction Deluxe Cross-Agent Scripting Vulnerability Source: CCN Type: BID-4070 MakeBid Auction Deluxe Plaintext Cookie Vulnerability Source: XF Type: UNKNOWN makebid-description-xss(8161) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |