CVE-2004-2123

Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and possibly (3) level parameter of ListCategories.asp.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextplace:e-commerce_asp_engine:*:*:*:*:*:*:*:*

Information

Published : 2004-12-31 05:00

Updated : 2017-07-11 01:31


NVD link : CVE-2004-2123

Mitre link : CVE-2004-2123


JSON object : View

Products Affected

nextplace

  • e-commerce_asp_engine