Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure

Bractus SunTrack Multiple XSS

 

 

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded


bugsnothugs at gmail

Nov 3, 2009, 4:21 PM

Post #1 of 1 (87 views)
Permalink
Bractus SunTrack Multiple XSS

Vendor: Bractus (http://bract.us)
Product: SunTrack (http://bract.us/demo/login.jsp)

Multiple stored XSS vulnerabilities exist in the Bractus SunTrack
courier software suite.

Affected scripts:
newprofile.html (title parameter)
signup/signup.html (firstname, lastname, company parameter)
contact.html (firstname, lastname, address[0].street1 parameter)

--

BugsNotHugs
Shared Vulnerability Disclosure Account

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.