Exploit Happymall E-Commerce Software 4.3/4.4 - 'Normal_HTML.cgi' Cross-Site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22588
Проверка EDB
  1. Пройдено
Автор
JULIO CESAR
Тип уязвимости
WEBAPPS
Платформа
CGI
CVE
cve-2003-0278
Дата публикации
2003-05-12
Код:
source: https://www.securityfocus.com/bid/7557/info

IT has been reported that Happymall E-Commerce is prone to cross-site scripting attacks. The problem occurs due to insufficient sanitization of user-supplied URI parameters. As a result, it may be possible for an attacker to execute arbitrary script code within the browser of a legitimate user visiting the site. 

http://www.target.com/shop/normal_html.cgi?file=<script>alert("XSS")</script>
 
Источник
www.exploit-db.com

Похожие темы