exploit-db-mirror/exploits/php/webapps/21377.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

9 lines
No EOL
487 B
Text

source: http://www.securityfocus.com/bid/4506/info
SunShop is commercial web store software. It is written in PHP, and will run on most Unix and Linux operating systems as well as Microsoft Windows.
SunShop allows attackers to embed arbitrary script code into form fields. This may enable a remote attacker to perform actions as the administrative user of the shopping cart.
Enter the following name when registering as a new customer:
blackhat<script>alert('ouch')</script>