Jump to content
Praetorian503

Shopping.com API Cross Site Scripting

Recommended Posts

Posted

The Shopping.com API V3 PHP script suffers from a cross site scripting vulnerability.

##################################################################################
__ _ _ ____
/ /___ _____ (_)_____________ ______(_)__ _____ / __ \_________ _
__ / / __ `/ __ \/ / ___/ ___/ __ `/ ___/ / _ \/ ___// / / / ___/ __ `/
/ /_/ / /_/ / / / / (__ |__ ) /_/ / / / / __(__ )/ /_/ / / / /_/ /
\____/\__,_/_/ /_/_/____/____/\__,_/_/ /_/\___/____(_)____/_/ \__, /
/____/
##################################################################################
Shopping.com Api V3 php Script, XSS Vulnerabilities
Software Page: http://en.clicsell.com/script-shopping-v3.html
Product Page: http://www.hotscripts.com/listing/shopping-com-api-v3-php-script/
Script Demo: http://en.clicsell.com/

Author(Pentester): 3spi0n
On Social: Twitter.Com/eyyamgudeer
Greetz: Grayhats Inc. and Janissaries Platform.
##################################################################################

[~] Xss on Demo Site (Searchbox)

>>> http://i.imgur.com/dIjfayE.png (Xss Found)
>>> If you try; you may open demo site and xss attack code to Searchbox.
>>> <script>alert('XSS')</script>

Source: PacketStorm

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...