Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

OSCommerce Account_History_Info.PHP HTML code injection Vulnerability

It has been reported that osCommerce is prone to HTML injection attacks. This problem occurs due to osCommerce insufficiently sanitizing user-supplied input.

As a result, attackers may embed malicious script code or HTML into orders.

This may make it possible to steal an unsuspecting user's cookie-based authentication credentials, as well as other sensitive information.

This vulnerability was reported to affect osCommerce version 2.2ms1, prior versions are reportedly affected.







 

Privacy Statement
Copyright 2009, SecurityFocus