CVE-2007-3324
Comersus Cart 7.07 - Cross-Site Scripting via redirectUrl Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-3324. PoCs published by Doz.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Comersus Cart 7.0.7, where the 'message' parameter in 'comersus_message.asp' is vulnerable to script injection. The example demonstrates how an attacker could inject malicious JavaScript or HTML forms to steal user credentials.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter to (1) comersus_customerAuthenticateForm.asp or (2) comersus_message.asp, different vectors than CVE-2004-0681.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in Comersus Cart 7.0.7, where the 'message' parameter in 'comersus_message.asp' is vulnerable to script injection. The example demonstrates how an attacker could inject malicious JavaScript or HTML forms to steal user credentials.
This exploit demonstrates a reflected XSS vulnerability in Comersus Cart by injecting a malicious script via the 'redirectUrl' parameter, which redirects users to a malicious executable. The vulnerability arises due to insufficient input validation.