5
CVSSv2

CVE-2001-1212

Published: 18/12/2001 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote malicious users to execute arbitrary Javascript via the desc parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

aktivate aktivate 1.03

Exploits

source: wwwsecurityfocuscom/bid/3714/info Aktivate is a shopping cart system which is geared towards Unix and Linux users, uses MySQL as a backend, and is written in Perl Aktivate is prone to cross-site scripting attacks It is possible to construct a link containing arbitrary script code to a website running Aktivate When a user brows ...