4.3
CVSSv2

CVE-2010-5018

Published: 02/11/2011 Updated: 17/11/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote malicious users to inject arbitrary web script or HTML via the sid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

2daybiz online classified script

Exploits

Name : 2daybiz online classified system SQLi AND XSS Vulnerability Date : june, 16 2010 Vendor url :www2daybizcom/online_classified_scripthtml Critical Level : HIGH Author : Sid3^effects aKa HaRi <shell_c99[at]yahoocom> special thanks to : r0073r (inj3ct0rcom),L0rd CruSad3r,MaYur,gunslinger_ greetz to :All ICW members and my frie ...