AOH :: HP Unsorted B :: BT-21929.HTM

Bractus SunTrack Multiple XSS



Bractus SunTrack Multiple XSS
Bractus SunTrack Multiple XSS



Vendor: Bractus (http://bract.us) 
Product: SunTrack (http://bract.us/demo/login.jsp) 

Multiple stored XSS vulnerabilities exist in the Bractus SunTrack
courier software suite.

Affected scripts:
newprofile.html (title parameter)
signup/signup.html (firstname, lastname, company parameter)
contact.html (firstname, lastname, address[0].street1 parameter)

-- 

BugsNotHugs
Shared Vulnerability Disclosure Account

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.