MEDIUM
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form
Published Mar 18, 2004
6.8
MEDIUMCVSS 2.0
EPSS 2.09%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.