Cross Site Scripting Vulnerability in McMurtrey/Whitaker & Associates' Cart32

Cart32 contains a cross-site scripting vulnerability that could let a potential remote attacker insert third-party content in a Web site.

Ken Pfeil

June 27, 2004

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported June 28, 2004, by DrPonidi.

VERSIONS AFFECTED

DESCRIPTION
Cart32 contains a cross-site scripting vulnerability that could let a potentialremote attacker insert third-party content in a Web site.

DEMONSTRATION
Any of thefollowing URLs can be used to trigger the vulnerability:
http://vulnerable/scripts/cart32.exe/GetLatestBuilds?cart32=
http://vulnerable/scripts/c32web.exe/GetLatestBuilds?cart32=
http://vulnerable/cgi-bin/cart32.exe/GetLatestBuilds?cart32=
http://vulnerable/cgi-bin/c32web.exe/GetLatestBuilds?cart32=

VENDOR RESPONSE
The vendor, McMurtrey/Whitaker& Associates, hasn't released a fix for this vulnerability.

CREDIT
Discovered by Dr Ponidi.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like