Cross Site Scripting in Nextplace.com E-Commerce Server

Nextplace.com E-Commerce ASP Engine is vulnerable to cross-site scripting.

ITPro Today

January 26, 2004

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported January 24, 2004 by RafelIvgi.

VERSIONS AFFECTED

  • NextPlace.com E-Commerce ASP Engine

DESCRIPTION

Nextplace.comE-Commerce ASP Engine is vulnerable to cross-site scripting. Bycrafting a specially formed URL, an attacker can cause code of his orher choice to run on the user's local system. The vulnerability can leadto manipulated Web content, stolen cookie data, or arbitrary actionsunder the context of the user's Web session.

VENDOR RESPONSE

Nextplace.comis aware of the problem.

CREDIT

Discoveredby Rafel Ivgi.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like