DPVision Tradingeye Shop Details.CFM Cross-Site Scripting Vulnerability
BID:18526
CVE-2006-3141 |Info
DPVision Tradingeye Shop Details.CFM Cross-Site Scripting Vulnerability
| Bugtraq ID: | 18526 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3141 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2006 12:00AM |
| Updated: | Jul 06 2016 01:33PM |
| Credit: | r0t discovered this vulnerability. |
| Vulnerable: |
DPVision Tradingeye Shop R4 |
| Not Vulnerable: |
DPVision Tradingeye Shop v5 |
Discussion
DPVision Tradingeye Shop Details.CFM Cross-Site Scripting Vulnerability
DPVision Tradingeye Shop is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
DPVision Tradingeye Shop is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
DPVision Tradingeye Shop Details.CFM Cross-Site Scripting Vulnerability
This issue can be exploited through a web client.
This issue can be exploited through a web client.
Solution / Fix
DPVision Tradingeye Shop Details.CFM Cross-Site Scripting Vulnerability
Solution:
The vendor released fixes to address this issue. Please contact the vendor for more information.
Solution:
The vendor released fixes to address this issue. Please contact the vendor for more information.
References
DPVision Tradingeye Shop Details.CFM Cross-Site Scripting Vulnerability
References:
References:
- Tradingeye Shop Product Page (DPVision)
- Tradingeye Shop R4 XSS (-Unsecured Systems-)