PT-2004-3303 · Vp Asp · Vp-Asp Shopping Cart
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-2411
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
VP-ASP Shopping Cart versions 4.0 through 5.0
Description:
The issue concerns the CleanseMessage function in shop$db.asp, which does not properly cleanse inputs. This allows remote attackers to conduct cross-site scripting (XSS) attacks without using parameter in "shopdisplayproducts.asp" or the
msg parameter in "shoperror.asp", and possibly other vectors.Recommendations:
For VP-ASP Shopping Cart versions 4.0 through 5.0, consider disabling the CleanseMessage function in shop$db.asp until a proper fix is available, and restrict access to the affected parameters
cat in "shopdisplayproducts.asp" and msg in "shoperror.asp" to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vp-Asp Shopping Cart