CyberStrong EShop 10browse.ASP SQL Injection Vulnerability
BID:14112
Info
CyberStrong EShop 10browse.ASP SQL Injection Vulnerability
| Bugtraq ID: | 14112 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2003 12:00AM |
| Updated: | Jun 30 2003 12:00AM |
| Credit: | Credit is given to [email protected] for discovering this vulnerability. |
| Vulnerable: |
CyberStrong eShop ASP Shopping Cart 4.2 |
| Not Vulnerable: | |
Discussion
CyberStrong EShop 10browse.ASP SQL Injection Vulnerability
CyberStrong eShop is prone to an SQL injection vulnerability. As a result, the attacker may modify the structure and logic of an SQL query that is made by the application. The attacker may accomplish this by passing malicious SQL syntax to the vulnerable '10browse.asp' script.
It is reported that the attacker may steal eShop authentication information. Other attacks may be possible depending on the capabilities of the underlying database and the nature of the affected query.
CyberStrong eShop is prone to an SQL injection vulnerability. As a result, the attacker may modify the structure and logic of an SQL query that is made by the application. The attacker may accomplish this by passing malicious SQL syntax to the vulnerable '10browse.asp' script.
It is reported that the attacker may steal eShop authentication information. Other attacks may be possible depending on the capabilities of the underlying database and the nature of the affected query.
Exploit / POC
CyberStrong EShop 10browse.ASP SQL Injection Vulnerability
The following example was provided:
http://www.example.com/eshop/10browse.asp?ProductCode='
The following example was provided:
http://www.example.com/eshop/10browse.asp?ProductCode='
Solution / Fix
CyberStrong EShop 10browse.ASP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CyberStrong EShop 10browse.ASP SQL Injection Vulnerability
References:
References: