Praetorian503 Posted February 17, 2013 Report Posted February 17, 2013 The Shopping.com API V3 PHP script suffers from a cross site scripting vulnerability.################################################################################## __ _ _ ____ / /___ _____ (_)_____________ ______(_)__ _____ / __ \_________ _ __ / / __ `/ __ \/ / ___/ ___/ __ `/ ___/ / _ \/ ___// / / / ___/ __ `// /_/ / /_/ / / / / (__ |__ ) /_/ / / / / __(__ )/ /_/ / / / /_/ / \____/\__,_/_/ /_/_/____/____/\__,_/_/ /_/\___/____(_)____/_/ \__, / /____/ ################################################################################## Shopping.com Api V3 php Script, XSS VulnerabilitiesSoftware Page: http://en.clicsell.com/script-shopping-v3.htmlProduct Page: http://www.hotscripts.com/listing/shopping-com-api-v3-php-script/Script Demo: http://en.clicsell.com/Author(Pentester): 3spi0nOn Social: Twitter.Com/eyyamgudeerGreetz: Grayhats Inc. and Janissaries Platform.##################################################################################[~] Xss on Demo Site (Searchbox)>>> http://i.imgur.com/dIjfayE.png (Xss Found)>>> If you try; you may open demo site and xss attack code to Searchbox.>>> <script>alert('XSS')</script>Source: PacketStorm Quote