[HSC Security Group] XSS in CartWiz

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hackers Center Security Group (http://www.hackerscenter.com/)          
Zinho's Security Advisory           

Desc: XSS in CartWIZ
Risk: Medium (Cookie stealing)


store/viewCart.asp?message=%3Cplaintext%3E

allows anyone to retrieve cookie and take control over the account.
I noticed there are also some unchecked input when a user log in into his account and change his own personal data.
This could lead to a permanent xss hole much more dangerous than the above.

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux