Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail parameter to owContactUs.asp, (2) bSub parameter to owListProduct.asp, or the (3) Name, (4) Email, or (5) Comment fields in owProductDetail.asp.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/13184 | exploit vdb entry patch |
http://securitytracker.com/id?1013720 | exploit vdb entry patch |
http://www.osvdb.org/15523 | vdb entry exploit |
http://www.securityfocus.com/bid/13186 | vdb entry patch |
http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab | url repurposed vendor advisory |
http://www.osvdb.org/15521 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20096 | vdb entry |
http://marc.info/?l=bugtraq&m=111352017704126&w=2 | mailing list |
http://www.osvdb.org/15522 | vdb entry exploit |
http://secunia.com/advisories/14969 | third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/13185 | exploit vdb entry patch |