lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
This website is powered by Openwall GNU/*/Linux security-enhanced OS
[<prev] [next>] [month] [year] [list]
Date: 1 Jan 2007 05:51:42 -0000
From: DoZ@...kersCenter.com
To: bugtraq@...urityfocus.com
Subject: AShop Shopping Cart Multiple XSS Vulnerabilities

Ashop Commerce provides a turn-key ecommerce solution with it's revolutionary online store building software. One of the worlds most easy to use web based administrations with award winning features allows the merchant to set up an online store capable of competing with the webs most powerful stores for a simple, low monthly fee. An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.



Description: AShop Shopping Cart Multiple XSS Vulnerabilities



Hackers Center Security Group (http://www.hackerscenter.com)
Doz's Advisory



Risk: Medium
Vendor: www.ashopsoftware.com
Class: cross-site scripting


Vulnerable: AShop Deluxe version 4.5.x & AShop Administration Panel


Exploit: Attackers can exploit these issues via a web client.


www.site.com/ashop/catalogue.php?cat=[XSS]

www.site.com/ashop/catalogue.php?exp=[XSS]

www.site.com/ashop/basket.php?cat=[XSS]

www.site.com/ashop/search.php?searchstring=[XSS]

www.site.com/ashop/shipping.php?action=checkout=[XSS]

www.site.com/ashop/shipping.php?action=[XSS] 

www.site.com/cart-path/admin/editcatalogue.php?cat=[XSS]

www.site.com/cart-path/admin/salesadmin.php?resultpage=[XSS]


Live Demo: www.ashopsoftware.com/deluxe-demo/admin/index.php

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux