Published:2006/04/10  Last Updated:2008/05/21

JVN#78363061
CAFEMILK Shopping Cart CGI cross-site scripting vulnerability

Overview

CAFEMILK Shopping Cart CGI contains a cross-site scripting vulnerability as it does not properly validate input strings.

Products Affected

  • CAFEMILK SHOPPING CART version 3.80 and earlier

Description

Impact

A malicious script may be executed on the user's web browser. Personal information, recorded in cookies issued by CAFEMILK SHOPPING CART CGI, may be leaked.

Solution

Vendor Status

Vendor Status Last Update Vendor Notes
SOHO WORKSHOP CAFEMILK Vulnerable 2006/04/14
Vendor Link
CAFEMILK SHOPPING CART http://cafemilk.milkcafe.to/

References

JPCERT/CC Addendum

Credit

Masashi Fujiwara reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2006-000609

Update History