Korean
<< Back
VID 21429
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The CactuShop has a 'popularlargeimage.asp' Cross-site Scripting Vulnerability.
CactuShop is an ASP application for running an e-commerce Web site for Microsoft Windows NT and Windows 2000 Server. CactuShop version 5.x are vulnerable to cross-site scripting vulnerability, caused by a failure of the application to properly validate user-supplied input in the 'popularlargeimage.asp' script. A remote attacker could create a specially crafted URL link to the 'popularlargeimage.asp' script containing malicious script code, and then could persuade a target user to click it. Once the URL is clicked, the embedded codes would be executed in the victim's Web browser. A remote attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=4787
http://securitytracker.com/alerts/2004/Mar/1009601.html

* Platforms Affected:
Cactusoft Ltd., CactuShop 5.x
Microsoft Windows Any version
Recommendation No upgrade or patch available as of June 2014.

Upgrade to the new version of CactuShop, when new version fixed this problem becomes available from the CactuShop Web Site at http://www.cactushop.com/
Related URL CVE-2004-1882 (CVE)
Related URL 10020 (SecurityFocus)
Related URL 15687 (ISS)