 |
|
|
Family: CGI abuses : XSS --> Category: infos
Comersus Cart Username Field HTML Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for username field HTML injection vulnerability in Comersus Cart
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains an ASP script that is affected by a
cross-site scripting flaw.
Description :
According to its banner, the remote host is running a version of
Comersus Cart that fails to properly sanitize user input to the
'Username' field. A possible hacker can exploit this vulnerability to cause
arbitrary HTML and script code to be executed by a user's browser in
the context of the affected web site when a user views the username
eg, in the admin pages.
Solution :
Upgrade to a version of Comersus Cart newer than 6.03.
Threat Level:
Low / CVSS Base Score : 2
(AV:R/AC:H/Au:NR/C:N/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|
|
|
|
|