mailing list archives
Click and Build eCommerce Platform Cross Site Scripting
From: Andrew Smith <stfunub () gmail com>
Date: Wed, 17 Nov 2004 16:13:17 +0000
Online eCommerce platform.
The vulnerability lies in the "listPos" variable in the script running
It does not properly secure user inputted variables, presumably as the
user is not supposed to input the variable but can do easily through
I was not able to find any other unchecked variables that are printed,
but there could be more.
More information and examples can be found here:
The vendor has been informed and claim to have fixed this problem.
Full-Disclosure - We believe in it.
- Click and Build eCommerce Platform Cross Site Scripting Andrew Smith (Nov 17)