-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Agoracgi v3.3e Cross Site Scripting Vulnerability Type: Cross Site Scripting Release Date: December 18, 2001 Product / Vendor: Agora.cgi is an open source ecommerce solution. Steve Kneizys is the principle author of this project. The project grew from a couple of other open source projects. http://www.agoracgi.com Summary: Cross Site Scripting, most dynamic websites are still not filtering user input. This lets remote sites access towrite scripts on vulnerable sites & application, stealing cookies, performing actions on behalf of user or modifying look of content on site. http://www.agoracgi.com/store/agora.cgi?cart_id=="http://www.securityoffice.net/images/title.gif"%20width=406%20border =0>&xm=on&product=HTML http://www.agoracgi.com/store/agora.cgi?cart_id=