Total Shop UK eCommerce Generic Cross-Site Scripting
16 Aug. 2012
Summary
The open source version of Total Shop UK eCommerce based on CodeIgniterversion 2.1.2 is subject to a cross-site scripting vulnerability. The valueof a generic parameter was not sufficiently sanitised before being writtento a block of Javascript code. An attacker could distribute a malicious URLthat would trigger this vulnerability and potentially steal session cookies,redirect the user to a malicious URL or download malware onto their machine.
Credit:
The information has been provided by Chris Cooper of Reaction Information Security.