[NT] Cart32 Cross-Site Scripting
From: SecuriTeam (support_at_securiteam.com)
Date: 06/28/04
- Previous message: SecuriTeam: "[UNIX] Cross-Site Scripting CuteNews (show_archives, show_news)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 28 Jun 2004 19:49:30 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Cart32 Cross-Site Scripting
------------------------------------------------------------------------
SUMMARY
<http://www.cart32.com/products.asp#Cart32> Cart32 is "a shopping cart
system for the e-commerce market". Cart32 has been found to contain a
cross site scripting vulnerability allowing a remote attacker to insert
third party content in to the web site.
DETAILS
Vulnerable Systems:
* Cart32 version 3.5a
* Cart32 version 4.5
* Cart32 version 5.0
Examples:
Any of the following URLs can be used to trigger the vulnerability:
http://vulnerable/scripts/cart32.exe/GetLatestBuilds?cart32=