Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  newsCMSlite (newsCMS.
mdb) Remote Password Disclosure Vulnerablity

  WWWBoard 2.0 Alpha 2 (passwd.txt) Password Disclosure Vulnerability

  TaskTracker All Version Remote Add Admin Exploit

  autoDealer <= 2.0 (iPro) Remote SQL Injection Vulnerability

From:Hackers Center Security Group <DoZ_(at)_hackerscenter.com>
Date:03.01.2007
Subject:AShop Shopping Cart Multiple XSS Vulnerabilities

Ashop Commerce provides a turn-key ecommerce solution with it's revolutionary online store building software. One of the worlds most easy to use web based administrations with award winning features allows the merchant to set up an online store capable of competing with the webs most powerful stores for a simple, low monthly fee. An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.



Description: AShop Shopping Cart Multiple XSS Vulnerabilities



Hackers Center Security Group (http://www.hackerscenter.com)
Doz's Advisory



Risk: Medium
Vendor: www.ashopsoftware.com
Class: cross-site scripting


Vulnerable: AShop Deluxe version 4.5.x & AShop Administration Panel


Exploit: Attackers can exploit these issues via a web client.


www.site.com/ashop/catalogue.php?cat=[XSS]

www.site.com/ashop/catalogue.php?exp=[XSS]

www.site.com/ashop/basket.php?cat=[XSS]

www.site.com/ashop/search.php?searchstring=[XSS]

www.site.com/ashop/shipping.php?action=checkout=[XSS]

www.site.com/ashop/shipping.php?action=[XSS]

www.site.com/cart-path/admin/editcatalogue.php?cat=[XSS]

www.site.com/cart-path/admin/salesadmin.php?resultpage=[XSS]


Live Demo: www.ashopsoftware.com/deluxe-demo/admin/index.php

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server