Cross Site Scripting Vulnerability in McMurtrey/Whitaker & Associates' Cart32
Cart32 contains a cross-site scripting vulnerability that could let a potential remote attacker insert third-party content in a Web site.
June 27, 2004
Reported June 28, 2004, by DrPonidi.
VERSIONS AFFECTED
DESCRIPTION
Cart32 contains a cross-site scripting vulnerability that could let a potentialremote attacker insert third-party content in a Web site.
DEMONSTRATION
Any of thefollowing URLs can be used to trigger the vulnerability:
http://vulnerable/scripts/cart32.exe/GetLatestBuilds?cart32=
http://vulnerable/scripts/c32web.exe/GetLatestBuilds?cart32=
http://vulnerable/cgi-bin/cart32.exe/GetLatestBuilds?cart32=
http://vulnerable/cgi-bin/c32web.exe/GetLatestBuilds?cart32=
VENDOR RESPONSE
The vendor, McMurtrey/Whitaker& Associates, hasn't released a fix for this vulnerability.
CREDIT
Discovered by Dr Ponidi.
About the Author
You May Also Like