[VIM] My Amazon Store Manager 1.0 - q or Keywords parameter?

Steven M. Christey coley at mitre.org
Mon Jan 23 13:52:03 EST 2006

Lovely little provenance issue for us ignorant types.



These VDBs claim that the affected parameter is "q".

I can't figure out where the VDBs got this, since there is no original
raw report.  OSVDB thankfully has an archive of the notification here:


but it contains this demonstration URL:


No "q" in sight.

What gives?

- Steve

Cross-site scripting (XSS) vulnerability in search.php in My Amazon
Store Manager 1.0 allows remote attackers to inject arbitrary web
script or HTML via the Keywords parameter.  NOTE: some sources claim
that the affected parameter is "q", but the only public archive of the
original researcher notification shows an XSS manipulation in

