Zen Cart Password_Forgotten.PHP SQL Injection Vulnerability
BID:15690
Info
Zen Cart Password_Forgotten.PHP SQL Injection Vulnerability
| Bugtraq ID: | 15690 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2005 12:00AM |
| Updated: | Feb 13 2006 10:53PM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
Zen Cart Web Shopping Cart 1.2.6 d Zen Cart Web Shopping Cart 1.1.2 d |
| Not Vulnerable: |
Zen Cart Web Shopping Cart 1.2.7 |
Discussion
Zen Cart Password_Forgotten.PHP SQL Injection Vulnerability
Zen Cart is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Zen Cart is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Zen Cart Password_Forgotten.PHP SQL Injection Vulnerability
No exploit is required.
The following proof of concept exploit is available:
No exploit is required.
The following proof of concept exploit is available:
Solution / Fix
Zen Cart Password_Forgotten.PHP SQL Injection Vulnerability
Solution:
The vendor has released an update to address this issue.
Zen Cart Web Shopping Cart 1.1.2 d
Zen Cart Web Shopping Cart 1.2.6 d
Solution:
The vendor has released an update to address this issue.
Zen Cart Web Shopping Cart 1.1.2 d
-
Zen Cart zen-cart-1-2-7-d_full-release.zip
http://prdownloads.sourceforge.net/zencart/zen-cart-1-2-7-d_full-relea se.zip -
ZenCart sql_injection_fix.zip
http://www.zen-cart.com/modules/mydownloads/
Zen Cart Web Shopping Cart 1.2.6 d
-
Zen Cart zen-cart-1-2-7-d_full-release.zip
http://prdownloads.sourceforge.net/zencart/zen-cart-1-2-7-d_full-relea se.zip -
ZenCart sql_injection_fix.zip
http://www.zen-cart.com/modules/mydownloads/
References
Zen Cart Password_Forgotten.PHP SQL Injection Vulnerability
References:
References:
- SQL Injection vulnerability fix (ZenCart)
- Vendor Home Page (Zen Cart)
- Zen-Cart <= 1.2.6d blind SQL injection / remote commands execution: (rgod)