PT-2005-4925 · Mysql Server · Mysql Auction

Published

2005-12-14

·

Updated

2011-03-08

·

CVE-2005-4237

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MySQL Auction versions 3.0 and earlier
Description A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the "SearchZoom" module.
Recommendations For MySQL Auction versions 3.0 and earlier, update to a version later than 3.0 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4237

Affected Products

Mysql Auction