Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
One more flaw in Happymall May 12 2003 04:19PM
Julio Cesar (e2fsck bol com br)


Happymall E-Commerce Directory Transversal Bug and Cross-site scripting

Vendor: Happycgi.com

Product: Happymall

Versions: 4.3, 4.4 (patched version too)

'normal_html.cgi' doesn't filter user-supplied input. The well-known

directory transversal

and cross-site scripting (XSS) vulnerab...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus