SecurityAlert : 2091 CVE : CVE-2007-0056 SecurityRisk : Low (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : Hackers Center Security Group Published : 05.01.2007
Affected Software :
AShop Shopping Cart
Advisory Content :
Ashop Commerce provides a turn-key ecommerce solution with it's
revolutionary online store building software. One of the worlds most easy
to use web based administrations with award winning features allows the
merchant to set up an online store capable of competing with the webs most
powerful stores for a simple, low monthly fee. An attacker may leverage
this issue to have arbitrary script code execute in the browser of an
unsuspecting user in the context of the affected site. This may help the
attacker steal cookie-based authentication credentials and launch other
attacks.
Live Demo: www.ashopsoftware.com/deluxe-demo/admin/index.php
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.