[UNIX] JShop page.php Cross Site Scripting
From: SecuriTeam (support_at_securiteam.com)
Date: 08/22/04
- Previous message: SecuriTeam: "[UNIX] PADS Simple Stack Overflow"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 22 Aug 2004 18:47:39 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
JShop page.php Cross Site Scripting
------------------------------------------------------------------------
SUMMARY
JShop is "a e-commerce system designed for servers that support both PHP
and MySQL. Featuring a wealth of features for high-end e-commerce systems,
such as customer accounts, stock control and order processing, JShop is
designed for those companies wanting to offer a greater level of service
to their on-line customers".
Due to inadequate filtering of user provided data, a remote attacker can
insert third-party content to the page returned to the users.
DETAILS
JShop inadequately filters incoming data of the xPage parameter, this
allows attackers to insert HTML and/or JavaScript to the data sent back to
the user.
Example:
http://vulnerable/page.php?xPage=