hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

qcred11
QUOTE


Advisory Name: Cart32 Input Validation Flaw in 'GetLatestBuilds?cart32=' Permits Remote Cross-Site Scripting Attacks
            Release Date: 12:50 AM 6/28/04
            Application: Cart32 Shopping Cart
            Author: Dr`Ponidi <drponidi_at_indonesia.or.id>
            Discover by: Dr`Ponidi <drponidi_at_indonesia.or.id>
Acknowledgments: Vulnerability discovery, exploit code, and advisory by Dr`Ponidi
            Vendor Status: The vendor has been contacted
            Vendor URL: http://www.cart32.com
            Reference: http://drponidi.5u.com/advisory.htm
            Greetz to: #indohack #dhegleng Sincan2[at]#malanghackerlink.net

Proof Of Concept:
http://vulnerable/scripts/cart32.exe/GetLa...</script>

http://vulnerable/scripts/c32web.exe/GetLa...</script>

http://vulnerable/cgi-bin/cart32.exe/GetLa...</script>

http://vulnerable/cgi-bin/c32web.exe/GetLa...</script>

[About Indonesia Security Development Team]
Indonesia Security Development Team researches and develops
intelligent, advanced application security assessment. Based in
Indonesia, Indonesia Security Development Team offers the best of
breed security consulting services, specializing in shopping carts
software and network security assessments. We provide security
information and patches for use by the entire network security
community.

This information is provided freely to all interested parties and may
be redistributed provided that it is not altered in any way, and that
the author is appropriately credited

Indonesia Security Development Team Advisory:
http://drponidi.5u.com/advisory.htm
_______________________________________________________________
Dr`Ponidi <drponidi_at_indonesia.or.id>

twistedps
a good find, yet questionable to its seriousness. Not much can be aquired with an xss script.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.