Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Comersus Cart Username Field HTML Injection Vulnerability

Comersus Cart is affected by a remote HTML injection vulnerability.

The problem presents itself when a malicious user enters HTML and script code through the Username field of the affected application. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Comersus Cart 6.03 is affected by this issue. Other versions may be vulnerable as well.







 

Privacy Statement
Copyright 2008, SecurityFocus