|
osCommerce Multiple Cross-Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI. Sample URIs have been provided: http://www.example.com/catalog/admin/banner_manager.php?page=1[XSS-code] http://www.example.com/catalog/admin/banner_statistics.php?page=1[XSS-code] http://www.example.com/catalog/admin/countries.php?page=1[XSS-code] http://www.example.com/catalog/admin/currencies.php?page=1[XSS-code] http://www.example.com/catalog/admin/languages.php?page=1[XSS-code] http://www.example.com/catalog/admin/manufacturers.php?page=1[XSS-code] http://www.example.com/catalog/admin/newsletters.php?page=1[XSS-code] http://www.example.com/catalog/admin/orders_status.php?page=1[XSS-code] http://www.example.com/catalog/admin/products_attributes.php?page=1[XSS-code] http://www.example.com/catalog/admin/products_expected.php?page=1[XSS-code] http://www.example.com/catalog/admin/reviews.php?page=1[XSS-code] http://www.example.com/catalog/admin/specials.php?page=1[XSS-code] http://www.example.com/catalog/admin/stats_products_purchased.php?page=1[XSS-code] http://www.example.com/catalog/admin/stats_products_viewed.php?page=1[XSS-code] http://www.example.com/catalog/admin/tax_classes.php?page=1[XSS-code] http://www.example.com/catalog/admin/tax_rates.php?page=1[XSS-code] http://www.example.com/catalog/admin/zones.php?page=1[XSS-code] http://www.example.com/catalog/admin/categories.php?action=new_product_preview&read=only&pID=12&origin=stats_products_viewed.php?page=2[XSS-code] |
|
|
Privacy Statement |