OneWorldStore DisplayResults.ASP Cross-Site Scripting Vulnerability
BID:13251
Info
OneWorldStore DisplayResults.ASP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 13251 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2005 12:00AM |
| Updated: | Apr 19 2005 12:00AM |
| Credit: | Lostmon <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
OneWorldStore OneWorldStore |
| Not Vulnerable: | |
Discussion
OneWorldStore DisplayResults.ASP Cross-Site Scripting Vulnerability
OneWorldStore is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
OneWorldStore is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
OneWorldStore DisplayResults.ASP Cross-Site Scripting Vulnerability
No exploit is required.
The following proof of concepts are available:
http://www.example.com/owSearch/DisplayResults.asp?sIDSearch=15"><META%20HTTP-EQUIV=Refresh%20CONTENT=0>
http://www.example.com/owSearch/DisplayResults.asp?sIDSearch=1"><h1>lalala</h1>
No exploit is required.
The following proof of concepts are available:
http://www.example.com/owSearch/DisplayResults.asp?sIDSearch=15"><META%20HTTP-EQUIV=Refresh%20CONTENT=0>
http://www.example.com/owSearch/DisplayResults.asp?sIDSearch=1"><h1>lalala</h1>
Solution / Fix
OneWorldStore DisplayResults.ASP Cross-Site Scripting Vulnerability
Solution:
The vendor has addressed this issue in their latest release of the application. Please see the referenced vendor advisory on obtaining and applying updates.
OneWorldStore OneWorldStore
Solution:
The vendor has addressed this issue in their latest release of the application. Please see the referenced vendor advisory on obtaining and applying updates.
OneWorldStore OneWorldStore
-
OneWorldStore OneWorldStore Current
http://oneworldstore.com/support_updates.asp
References
OneWorldStore DisplayResults.ASP Cross-Site Scripting Vulnerability
References:
References:
- OneWorldStore Homepage (OneWorldStore)
- OneWorldStore Security Advisories (OneWorldStore)