Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
From: YGN Ethical Hacker Group (listsyehg.net)
Date: Thu Feb 24 2011 - 23:11:49 CST
PHPShop 0.8.1 <= | Cross Site Scripting Vulnerability
The PHPShop 0.8.1 and lower versions are currently vulnerable to Cross
PHPShop is a PHP-powered shopping cart application. It is released
under the GNU General Public License.
The primary purpose of PHPShop is to provide a simple shopping cart
solution that is easy to customize to suit any purpose. PHPShop has
less features that many other shopping cart applications, but is
generally easier to customize.
3. VULNERABILITY DESCRIPTION
The Query String was not properly sanitized upon submission to the
/index.php url, which allows attacker to conduct Cross Site Scripting
This may allow an attacker to create a specially crafted URL that
would execute arbitrary script code in a victim's browser.
4. VERSIONS AFFECTED
PHP 0.8.1 <=
The vendor has discontinued this product.
It is recommended that an alternate software package be used in its place.
PHPShop Development Team
This vulnerability was discovered by Aung Khant, http://yehg.net, YGN
Ethical Hacker Group, Myanmar.
9. DISCLOSURE TIME-LINE
2011-02-25: vulnerability disclosed
Original Advisory URL:
Project Home: http://code.google.com/p/phpshop/,
PHPShop Download Stats:
XSS (owasp): http://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
YGN Ethical Hacker Group
Our Lab | http://yehg.net/lab
Our Directory | http://yehg.net/hwd
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/