CaupoShop User Information Cross-Agent Scripting Vulnerability
BID:4270
Info
CaupoShop User Information Cross-Agent Scripting Vulnerability
| Bugtraq ID: | 4270 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0439 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Published by ppp-design <[email protected]>. |
| Vulnerable: |
Caupo.net CaupoShop 1.30 rc4 Caupo.net CaupoShop 1.30 a |
| Not Vulnerable: | |
Discussion
CaupoShop User Information Cross-Agent Scripting Vulnerability
CaupoShop is a web based shopping cart system. CaupoShop is implemented in PHP, and may be found on Linux, Windows or other Unix based systems.
A cross-agent scripting vulnerability has been reported in some versions of CaupoShop. When a user is created, JavaScript code may be included in most of the fields associated with that user. If an administrator then views the maliciously created user, the script will be displayed and interpreted in the context of the CaupoShop administration page.
This vulnerability may also exist in earlier versions of CaupoShop, or in CaupoShopPro. This has not been confirmed.
CaupoShop is a web based shopping cart system. CaupoShop is implemented in PHP, and may be found on Linux, Windows or other Unix based systems.
A cross-agent scripting vulnerability has been reported in some versions of CaupoShop. When a user is created, JavaScript code may be included in most of the fields associated with that user. If an administrator then views the maliciously created user, the script will be displayed and interpreted in the context of the CaupoShop administration page.
This vulnerability may also exist in earlier versions of CaupoShop, or in CaupoShopPro. This has not been confirmed.
Exploit / POC
CaupoShop User Information Cross-Agent Scripting Vulnerability
No exploit is required.
No exploit is required.