New Zenner
- Join Date:
- Jun 2006
- Posts:
- 21
- Plugin Contributions:
- 0
[FIX] v1.3.5 XSS Exploits Found
Not sure if you guys saw this one yet already, just wanted to give you a heads up.
Armorize Technologies Security Advisory
Advisory No:
Armorize-ADV-2006-0003
Date:
2006/9/27
Summary:
Armorize-ADV-2006-0003 discloses multiple cross-site scripting vulnerabilities that are found in Zen Cart, which is a PHP e-commerce shopping program and is Built on a foundation of OScommerce GPL code. It provides an easy-to-setup and run online store.
Affected Software:
Zen Cart 1.3.5
Vulnerability Description:
Cross-Site Scripting
Analysis/Impact:
Privacy leakages from the client-side may lead to session hijacking, identity theft and information theft.
Detection/Exploit(partial):
http://www.example.com/[PATH]/login.php
http://www.example.com/[PATH]/password_forgotten.php
Protection/Solution:
- Escape every questionable URI and HTML script.
- Remove prohibited user input.
Credit: Security Team at Armorize Technologies, Inc. ([email protected])
Additional Information:
Link to this Armorize advisory
http://www.armorize.com/advisory.php?Keyword=Armorize-ADV-2006-0002
Links to all Armorize advisories
http://www.armorize.com/advisory/
Links to Armorize vulnerability database
http://www.armorize.com/resources/vulnerability.php
advertising removed