Comersus Shopping Cart http response splitting hole

Comersus Shopping Cart http response splitting hole
ADVISORY: http response splitting hole in Comersus shopping cart

Author: Maestro (me!)
Date: 01-SEP-04
Vendor: Comersus ( 
Product: Comersus Shopping Cart 5.0991
Problem: Http response splitting (web cache poisoning, xss, 
yadayadayada) - sponse.pdf



(replace curly braces with lessthan and greaterthan)

Vendor status: vendor was contacted (attempt) several times over the 
last two weeks, by their bug report form, and by emal to support. No 
response so far. 

