<p><strong>Overview</strong><br><a href="http://wwww.shopathometv.com/">http://wwww.shopathometv.com</a>, A popular website whos television program runs late night on local syndicated television is vulnerable to multiple xxs flaws. While shopping their site last night, they did not have a product I was looking for when I entered an item number so I decided to test a few things.
<br> <br><strong>1st Bug</strong><br> <br>The main search box input is not sanitized on the front page. Simply go to <a href="http://www.shopathometv.com/">http://www.shopathometv.com</a> and in their product search box type in <script>alert(
document.cookie );</script> hit the Go inside the circle. When the page finishes loading if you are a user signed up (have'nt tested not signed up) you will get displayed all of your session variables.<br> <br><strong>
2nd Bug</strong><br> <br>On the The following page there is an xxs inside the showTitle GET variable. Click the link below<br><a href="https://www.shopathometv.com/programguide/thumbnail.jsp?date=null&showId=3203180&showTitle=<script>alert(document.cookie);</script>&sortType=Best%20Selling">
https://www.shopathometv.com/programguide/thumbnail.jsp?date=null&showId=3203180&showTitle=<script>alert(document.cookie);</script>&sortType=Best%20Selling</a> <br> <br><strong>Fix<br></strong>Sanitize all input variables.
<br> <br><strong>Conclusion</strong><br>will not be shopping there until this is fixed.<br> <br>-suckure</p>