about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MetaCart E-Shop ProductsByCategory.ASP Cross-Site Scripting Vulnerability


Title MetaCart E-Shop ProductsByCategory.ASP Cross-Site Scripting Vulnerability
Published 2005-05-16-12:00AM
Updated 2005-05-16-04:58PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  dedi dwianto <the_day@echo.or.id> is credited with the discovery of this vulnerability.
Vulnerable  MetaLinks MetaCart2 for SQL Server UK Edition
MetaLinks MetaCart2 for PayPal
MetaLinks MetaCart2 for PayFlow Link
MetaLinks MetaCart Free
MetaLinks MetaCart eShop V8
Not Vulnerable  
Code   No exploit is required.

The following proof of concept URI is available:
http://www.example.com/mcartlite/productsByCategory.asp?intCatalogID=1&strCatalog_NAME=&lt;script&gt;alert('test')&lt;/script&gt;
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 10:25:09 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c sexy pict invision P news for c www.porns. video gadi news for c sniffer Crack Data serdar ort php-fusion Www.Simran BoolYWOODS smf 1 0 nepali xchat news for c news for c t363t Crack Data serv t227t www.namith free full www.js008. mambo Remo www.80845. library/li Crack Data lo107l remote fil Unclassif maxcpm.inf www.80845. AllMyGuest t33t victoria.h sexbb skin/zero_ Sexe giris domain0 anmal girl www.deyi98 zeebra sex maxcpm.inf SEX 20 VID 200 /compo Crack Data jaybarathi jestin tem