lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060915153716.8878.qmail@securityfocus.com> Date: 15 Sep 2006 15:37:16 -0000 From: meto5757@...mail.com To: bugtraq@...urityfocus.com Subject: NextAge Cart Cross-Site Scripting multiple Vulnerabilities Vulnerable:NextAge Cart Cross-Site Scripting Vulnerability. Venedor site : http://www.nextagecart.com Critical Level : Dangerous Exploiting this issue could allow an attacker to steal cookie-based authentication credentials and to launch other attacks. Exploit : http://www.example.com/[path]/index.php?main=category&sub=product&CatId=[xss] http://www.example.com/[path]/index.php?SearchOpt=1&main=search&sub=index&SearchWd=[xss]