vendor site:http://www.webinhabit.com/ product:A+ Store E-Commerce bug:injection sql & xss post risk:medium injection sql (get) : http://site.com/browse.asp?ParentID='[sql] xss post : in /account_login.asp: username = '">'"> passwd = '">'"> laurent gaffié & benjamin mossé http://s-a-p.ca/ contact: saps.audit@gmail.com