Comersus BackOffice Multiple Input Validation And Information Disclosure Vulnerabilities
BID:15251
Info
Comersus BackOffice Multiple Input Validation And Information Disclosure Vulnerabilities
| Bugtraq ID: | 15251 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2005 12:00AM |
| Updated: | Oct 31 2005 12:00AM |
| Credit: | _6mO_HaCk is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Comersus Open Technologies BackOffice Plus 6.0.1 Comersus Open Technologies BackOffice Plus 6.0 Comersus Open Technologies BackOffice Plus 5.0 9 Comersus Open Technologies BackOffice Plus 5.0 Comersus Open Technologies BackOffice Plus 4.32 Comersus Open Technologies BackOffice Plus 4.30 Comersus Open Technologies BackOffice Plus 4.11 Comersus Open Technologies BackOffice Plus 4.10 Comersus Open Technologies BackOffice Plus 4.5 Comersus Open Technologies BackOffice Plus 4.2 Comersus Open Technologies BackOffice Plus Comersus Open Technologies BackOffice Lite 6.0.1 Comersus Open Technologies BackOffice Lite 6.0 Comersus Open Technologies BackOffice Lite 5.0 9 Comersus Open Technologies BackOffice Lite 5.0 Comersus Open Technologies BackOffice Lite 4.32 Comersus Open Technologies BackOffice Lite 4.30 Comersus Open Technologies BackOffice Lite 4.11 Comersus Open Technologies BackOffice Lite 4.10 Comersus Open Technologies BackOffice Lite 4.5 Comersus Open Technologies BackOffice Lite 4.2 Comersus Open Technologies BackOffice Lite |
| Not Vulnerable: | |
Discussion
Comersus BackOffice Multiple Input Validation And Information Disclosure Vulnerabilities
Comersus BackOfficePlus and BackOfficeLite are prone to multiple input validation and information disclosure vulnerabilities.
The applications are prone to SQL injection attacks, information disclosure and multiple cross-site scripting attacks.
An attacker can exploit these vulnerabilities to retrieve sensitive and privileged information, gain access to the application as an administrative user and perform cross-site scripting attacks to retrieve cookie-based authentication credentials from victim users; other attacks are also possible.
Comersus BackOfficePlus and BackOfficeLite are prone to multiple input validation and information disclosure vulnerabilities.
The applications are prone to SQL injection attacks, information disclosure and multiple cross-site scripting attacks.
An attacker can exploit these vulnerabilities to retrieve sensitive and privileged information, gain access to the application as an administrative user and perform cross-site scripting attacks to retrieve cookie-based authentication credentials from victim users; other attacks are also possible.
Exploit / POC
Comersus BackOffice Multiple Input Validation And Information Disclosure Vulnerabilities
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/comersus/backofficelite/comersus_backoffice_message.asp?message=<script>alert('vul');</script>
http://www.example.com/comersus/backofficeplus/comersus_backoffice_message.asp?message=<script>alert('vul');</script>
http://www.example.com/comersus/backofficePlus/comersus_backoffice_supportError.asp?error=<script>alert('vul');</script>
The following proof of concept exploit is also available:
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/comersus/backofficelite/comersus_backoffice_message.asp?message=<script>alert('vul');</script>
http://www.example.com/comersus/backofficeplus/comersus_backoffice_message.asp?message=<script>alert('vul');</script>
http://www.example.com/comersus/backofficePlus/comersus_backoffice_supportError.asp?error=<script>alert('vul');</script>
The following proof of concept exploit is also available:
Solution / Fix
Comersus BackOffice Multiple Input Validation And Information Disclosure Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Comersus BackOffice Multiple Input Validation And Information Disclosure Vulnerabilities
References:
References:
- Comersus Cart Homepage (Comersus Open Technologies)