Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

osCommerce Multiple Cross-Site Scripting Vulnerabilities

To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.

Sample URIs have been provided:

http://www.example.com/catalog/admin/banner_manager.php?page=1[XSS-code]
http://www.example.com/catalog/admin/banner_statistics.php?page=1[XSS-code]
http://www.example.com/catalog/admin/countries.php?page=1[XSS-code]
http://www.example.com/catalog/admin/currencies.php?page=1[XSS-code]
http://www.example.com/catalog/admin/languages.php?page=1[XSS-code]
http://www.example.com/catalog/admin/manufacturers.php?page=1[XSS-code]
http://www.example.com/catalog/admin/newsletters.php?page=1[XSS-code]
http://www.example.com/catalog/admin/orders_status.php?page=1[XSS-code]
http://www.example.com/catalog/admin/products_attributes.php?page=1[XSS-code]
http://www.example.com/catalog/admin/products_expected.php?page=1[XSS-code]
http://www.example.com/catalog/admin/reviews.php?page=1[XSS-code]
http://www.example.com/catalog/admin/specials.php?page=1[XSS-code]
http://www.example.com/catalog/admin/stats_products_purchased.php?page=1[XSS-code]
http://www.example.com/catalog/admin/stats_products_viewed.php?page=1[XSS-code]
http://www.example.com/catalog/admin/tax_classes.php?page=1[XSS-code]
http://www.example.com/catalog/admin/tax_rates.php?page=1[XSS-code]
http://www.example.com/catalog/admin/zones.php?page=1[XSS-code]
http://www.example.com/catalog/admin/categories.php?action=new_product_preview&read=only&pID=12&origin=stats_products_viewed.php?page=2[XSS-code]







 

Privacy Statement
Copyright 2009, SecurityFocus