AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
January 07, 2009, 11:21:05 AM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 5327 Members
Latest Member: koliangoodsb
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Topic: OS Commerce Alert! 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: OS Commerce Alert!  (Read 521 times)
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
OS Commerce Alert!
« on: February 18, 2005, 11:53:53 PM »

If you are running OS Commerce, please test your site for this vulnerability and be sure to stay on top of patches and upgrades that may become available from the OSCommerce support website.

 K-OTik Security Advisory : KOTIK/ADV-2005-0171
CVE Reference : CAN-2005-0458
Rated as : Low
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-02-16

 * Technical Description *

A new vulnerability was reported in osCommerce, which can be exploited by attackers to conduct Cross Site Scripting attacks. The problem resides in the "contact_us.php" file when handling the "enquiry" parameter, which may be exploited to cause arbitrary scripting code to be executed by the user's browser.

http://site/contact_us.php?&name=1&email=1&enquiry=[XSS]

 * Affected Products *

osCommerce version 2.2-MS2 and prior

 * Solution *

K-OTik Security is not aware of any official supplied patch for this issue.

 * References *

http://www.k-otik.com/english/advisories/2005/0171
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Topic: OS Commerce Alert! « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!