[39911] in bugtraq

home help back first fref pref prev next nref lref last post

[HSC Security Group] XSS in CartWiz

daemon@ATHENA.MIT.EDU (zinho@hackerscenter.com)
Tue Jul 26 15:17:18 2005

Date: 26 Jul 2005 15:29:41 -0000
Message-ID: <20050726152941.24688.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: zinho@hackerscenter.com
To: bugtraq@securityfocus.com

Hackers Center Security Group (http://www.hackerscenter.com/)          
Zinho's Security Advisory           

Desc: XSS in CartWIZ
Risk: Medium (Cookie stealing)


store/viewCart.asp?message=%3Cplaintext%3E

allows anyone to retrieve cookie and take control over the account.
I noticed there are also some unchecked input when a user log in into his account and change his own personal data.
This could lead to a permanent xss hole much more dangerous than the above.

home help back first fref pref prev next nref lref last post