>> VP-ASP Shopping Cart "UserName" Cross Site Scripting Vulnerability
Title : VP-ASP Shopping Cart "UserName" Cross Site Scripting Vulnerability VUPEN ID : VUPEN/ADV-2005-2486 CVE ID : CVE-2005-3685
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-11-18
Technical Description
A vulnerability has been identified in VP-ASP Shopping Cart, which may be exploited by attackers to inject malicious HTML code. This flaw is due to an input validation error in the "shopadmin.asp" script when processing a specially crafted "UserName" parameter, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.