|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Tamer Sahin (ts
securityoffice.net)Date: Mon Dec 17 2001 - 16:30:49 CST
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Agoracgi v3.3e Cross Site Scripting Vulnerability
Type:
Cross Site Scripting
Release Date:
December 18, 2001
Product / Vendor:
Agora.cgi is an open source ecommerce solution. Steve Kneizys is the
principle author of this project. The project grew from a couple of
other open source projects.
Summary:
Cross Site Scripting, most dynamic websites are still not filtering
user input. This lets remote sites access towrite scripts on
vulnerable sites & application, stealing cookies, performing actions
on behalf of user or modifying look of content on site.
http://www.agoracgi.com/store/agora.cgi?cart_id=
="http://www.securityoffice.net/images/title.gif"%20width=406%20border
=0>&xm=on&product=HTML