[原文]Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, as demonstrated by the (1) query parameter in search.php and the (2) data parameter in search_cat.php.
CosmicShoppingCart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the \'query\' variable upon submission to the search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user\'s browser within the trust relationship between the browser and the server, leading to a loss of integrity.
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
Marcelo Almeida is credited with the discovery of these vulnerabilities.
CosmicPHP CosmicShoppingCart 0
CosmicShoppingCart is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to compromise the application, access or modify data, steal cookie-based authentication credentials, or exploit vulnerabilities in the underlying database implementation. Other attacks may also be possible.
Attackers can use a web browser to exploit these vulnerabilities.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: firstname.lastname@example.org:email@example.com.