LaGarde StoreFront Shopping Cart LOGIN.ASP SQL Injection Vulnerability
BID:13998
Info
LaGarde StoreFront Shopping Cart LOGIN.ASP SQL Injection Vulnerability
| Bugtraq ID: | 13998 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0557 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2003 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to G00db0y. |
| Vulnerable: |
LaGarde StoreFront 5.0 |
| Not Vulnerable: |
LaGarde StoreFront 6.0 LaGarde StoreFront 5.0 .4014 |
Discussion
LaGarde StoreFront Shopping Cart LOGIN.ASP SQL Injection Vulnerability
StoreFront Shopping Cart is affected by an SQL injection vulnerability. The vulnerability affects the 'login.asp' script.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
StoreFront Shopping Cart 5.0 is affected by this vulnerability.
StoreFront Shopping Cart is affected by an SQL injection vulnerability. The vulnerability affects the 'login.asp' script.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
StoreFront Shopping Cart 5.0 is affected by this vulnerability.
Exploit / POC
LaGarde StoreFront Shopping Cart LOGIN.ASP SQL Injection Vulnerability
An exploit is not required.
The following proof of concept example is available:
Email id: [email protected]
Password: ' or '='
An exploit is not required.
The following proof of concept example is available:
Email id: [email protected]
Password: ' or '='
Solution / Fix
LaGarde StoreFront Shopping Cart LOGIN.ASP SQL Injection Vulnerability
Solution:
Storefront versions 50.4014 and subsequent versions are not affected by this issue. Please contact the vendor to obtain fixes.
Solution:
Storefront versions 50.4014 and subsequent versions are not affected by this issue. Please contact the vendor to obtain fixes.
References
LaGarde StoreFront Shopping Cart LOGIN.ASP SQL Injection Vulnerability
References:
References: