Cross Site Scripting in Nextplace.com E-Commerce Server
Nextplace.com E-Commerce ASP Engine is vulnerable to cross-site scripting.
ITPro Today
January 26, 2004
1 Min Read
Reported January 24, 2004 by RafelIvgi.
VERSIONS AFFECTED
NextPlace.com E-Commerce ASP Engine
DESCRIPTION
Nextplace.comE-Commerce ASP Engine is vulnerable to cross-site scripting. Bycrafting a specially formed URL, an attacker can cause code of his orher choice to run on the user's local system. The vulnerability can leadto manipulated Web content, stolen cookie data, or arbitrary actionsunder the context of the user's Web session.
VENDOR RESPONSE
Nextplace.comis aware of the problem.
CREDIT
Discoveredby Rafel Ivgi.
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like