Cross-Site Scripting Vulnerability in Mewsoft Auction Script
12 Jul. 2002
Summary
Mewsoft Auction a web based auction engine has been found to contain a security vulnerability that would allow attackers to cause a cross-site scripting vulnerability.
Credit:
The information has been provided by ? o m e 1.
Example:
For example accessing the following URL will cause an alert to pop up: http://www.xxxx.com/cgi-bin/auction/auction.cgi?action=Sort_Page&View=Search
&Page=0&Cat_ID=&Lang=English&Search=All&Terms=<scr!pt>alert('OopS');</script
>&Where=&Sort=Photo&Dir=