MyMarket Form_Header.PHP Cross-Site Scripting Vulnerability
BID:6035
Info
MyMarket Form_Header.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 6035 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2002 12:00AM |
| Updated: | Oct 23 2002 12:00AM |
| Credit: | Disvoery of this issue is credited to "qber66" <[email protected]>. |
| Vulnerable: |
MyMarket MyMarket 1.71 |
| Not Vulnerable: | |
Discussion
MyMarket Form_Header.PHP Cross-Site Scripting Vulnerability
MyMarket is prone to cross-site scripting attacks.
HTML tags and script code are not sanitized from CGI variables which may cause user-supplied input to be displayed. As a result, an attacker can create a link to a site running the vulnerable software which contains malicious attacker-supplied HTML and script code.
When this link is visited, the attacker-supplied code will execute in the user's web client in the security context of the site hosting the software.
MyMarket is prone to cross-site scripting attacks.
HTML tags and script code are not sanitized from CGI variables which may cause user-supplied input to be displayed. As a result, an attacker can create a link to a site running the vulnerable software which contains malicious attacker-supplied HTML and script code.
When this link is visited, the attacker-supplied code will execute in the user's web client in the security context of the site hosting the software.
Exploit / POC
MyMarket Form_Header.PHP Cross-Site Scripting Vulnerability
The following proof-of-concept example was provided:
http://www.example.com/templates/form_header.php?noticemsg=<Script>javascript:alert(document.cookie)</Script>
The following proof-of-concept example was provided:
http://www.example.com/templates/form_header.php?noticemsg=<Script>javascript:alert(document.cookie)</Script>
Solution / Fix
MyMarket Form_Header.PHP Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MyMarket Form_Header.PHP Cross-Site Scripting Vulnerability
References:
References:
- MyMarket Homepage (MyMarket)