6.8
CVSSv2

CVE-2006-6768

Published: 27/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in default.asp in PWP Technologies The Classified Ad System allow remote malicious users to inject arbitrary web script or HTML via the (1) cat or (2) main parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

pwp technologies the classified ad system

Exploits

source: wwwsecurityfocuscom/bid/21198/info The Classified Ad System is prone to multiple input-validation vulnerabilities, including SQL-injection issues and a cross-site scripting issue, because it fails to sufficiently sanitize user-supplied data Exploiting these issues could allow an attacker to steal cookie-based authentication cred ...