Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/246044 | mailing list vendor advisory |
http://www.iss.net/security_center/static/7708.php | vdb entry vendor advisory |
http://www.securityfocus.com/bid/3702 | exploit vdb entry patch vendor advisory |
http://www.agoracgi.com/security.html | url repurposed |
http://www.osvdb.org/698 | vdb entry |