IDP Signatures

67935 errmsg.gen_confirm.E-PhpB2BTradingMarketplace.XSS.A

Back to list
Signature Id 67935
Name errmsg.gen_confirm.E-PhpB2BTradingMarketplace.XSS.A
Group IPS WEB XSS
Issued 2010-06-14
Last Updated 2010-12-01
Description A cross site scripting vulnerability exists in the E-Php B2B Trading Marketplace web application due to insufficient user input sanitation of the 'errmsg' parameter to the gen_confirm.php page. An attacker could exploit this to execute arbitrary HTML and script code in the user's session.