Ultimate Auction versions 3.67 and below suffer from cross site scripting flaws.
9128386042efd1779d1c7c56f599177b0f4f184a4a37715ff86f4358c23d98db
Hello!
I've found a XSS in Ultimate Auction <=3.67. The Vendor was informed mid
October 2005! They still haven't fix the script and doesn't reply to mails.
Here's a little Example:
https://www.ultimate-auction.de/cgi-local/auktion/item.pl/item.pl?item=<script>alert("XSS")</script>
https://www.ultimate-auction.de/cgi-local/auktion/itemlist.pl?category=<script>alert("XSS")</script>
The bug has the BID 16239