CVE-2004-2123

Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and possibly (3) level parameter of ListCategories.asp.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextplace:e-commerce_asp_engine:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2004-12-31 05:00

Updated : 2024-02-04 16:31


NVD link : CVE-2004-2123

Mitre link : CVE-2004-2123

CVE.ORG link : CVE-2004-2123


JSON object : View

Products Affected

nextplace

  • e-commerce_asp_engine