Exploit Alan Ward A-Cart 2.0 - MSG Cross-Site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
23195
Проверка EDB
  1. Пройдено
Автор
G00DB0Y
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
null
Дата публикации
2003-09-29
Код:
source: https://www.securityfocus.com/bid/8722/info

A-Cart has been reported prone to a cross-site scripting vulnerability. The issue presents itself likely due to a lack of sufficient sanitization performed on data contained in the 'msg' URI parameter that is passed to signin.asp.

An attacker could exploit this condition to render arbitrary HTML in the browser of a victim, stealing cookie authentication credentials or performing other nefarious acts. 

http://www.example.com/acartpath/signin.asp?msg=<script>alert('Zone-h')</script>
 
Источник
www.exploit-db.com

Похожие темы