No account yet?
Home » HSC Research » Advisories » [HSC] Cross Site Scripting in CartWiz
[HSC] Cross Site Scripting in CartWiz E-mail
HSC Research Group - Advisories
Written by Hackers Center   
Tuesday, 26 July 2005 16:11
Hackers Center Security Group (http://www.hackerscenter.com/)
Zinho"s Security Advisory

Desc: XSS in CartWIZ
Risk: Medium (Cookie stealing)


store/viewCart.asp?message=%3Cplaintext%3E

allows anyone to retrieve cookie and take control over the account.
I noticed there are also some unchecked input when a user log in into his account and change his own personal data.
This could lead to a permanent xss hole much more dangerous than the previous.



 

Security Services by HSC