|
HSC Research Group -
Advisories
|
|
Written by Hackers Center
|
|
Tuesday, 26 July 2005 16:11 |
Hackers Center Security Group (http://www.hackerscenter.com/) Zinho"s Security Advisory
Desc: XSS in CartWIZ Risk: Medium (Cookie stealing)
store/viewCart.asp?message=%3Cplaintext%3E
allows anyone to retrieve cookie and take control over the account. I noticed there are also some unchecked input when a user log in into his account and change his own personal data. This could lead to a permanent xss hole much more dangerous than the previous.
|