CVE-2009-0430 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.2% (pctl 67)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.19% — more likely to be exploited than 67% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-02-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| activewebsoftwares | active bids |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Active Bids - 'search' Cross-Site Scripting | 2009-01-15 |
References
→ the Explorer · watch your stack · NVD