Description
|
|
Two vulnerabilities were identified in Comersus Cart, which could be exploited by attackers to perform SQL injection and cross site scripting.
- The first issue is due to an input validation error in ""comersus_backoffice_listAssignedPricesToCustomer.asp" and "comersus_backoffice_message.asp" when processing specially crafted "name" and "message" parameters, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.
- The second vulnerability is due to an input validation error in "comersus_optReviewReadExec.asp" when processing a specially crafted "idProduct" variable, which may be exploited by remote users to conduct SQL injection attacks.
|