Happymall E-Commerce Software Normal_HTML.CGI Cross-Site Scripting Vulnerability
BID:7557
Info
Happymall E-Commerce Software Normal_HTML.CGI Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7557 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2003 12:00AM |
| Updated: | May 12 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Julio Cesar <[email protected]>. |
| Vulnerable: |
HappyCGI HappyMall 4.4 HappyCGI HappyMall 4.3 |
| Not Vulnerable: | |
Discussion
Happymall E-Commerce Software Normal_HTML.CGI Cross-Site Scripting Vulnerability
IT has been reported that Happymall E-Commerce is prone to cross-site scripting attacks. The problem occurs due to insufficient sanitization of user-supplied URI parameters. As a result, it may be possible for an attacker to execute arbitrary script code within the browser of a legitimate user visiting the site.
IT has been reported that Happymall E-Commerce is prone to cross-site scripting attacks. The problem occurs due to insufficient sanitization of user-supplied URI parameters. As a result, it may be possible for an attacker to execute arbitrary script code within the browser of a legitimate user visiting the site.
Exploit / POC
Happymall E-Commerce Software Normal_HTML.CGI Cross-Site Scripting Vulnerability
No exploit is required.
The following proof of concept URL has been made available:
http://www.target.com/shop/normal_html.cgi?file=<script>alert("XSS")</script>
No exploit is required.
The following proof of concept URL has been made available:
http://www.target.com/shop/normal_html.cgi?file=<script>alert("XSS")</script>
Solution / Fix
Happymall E-Commerce Software Normal_HTML.CGI Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Happymall E-Commerce Software Normal_HTML.CGI Cross-Site Scripting Vulnerability
References:
References:
- One more flaw in Happymall (Julio Cesar
)