AFCommerce Shopping Cart Multiple Input Validation Vulnerabilities
BID:19074
CVE-2006-3794 | CVE-2006-3800 |Info
AFCommerce Shopping Cart Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 19074 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2006 12:00AM |
| Updated: | Jul 20 2006 06:12PM |
| Credit: | Sledge is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
AFFCommerce Shopping Cart AFFCommerce Shopping Cart 1.1.4 |
| Not Vulnerable: | |
Discussion
AFCommerce Shopping Cart Multiple Input Validation Vulnerabilities
AFCommerce Shopping Cart is prone to multiple input-validation vulnerabilities. The issues include HTML- and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploits of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
Reports indicate that the 'Demo Store' version is affected by these vulnerabilities; other versions may also be affected.
Vendor reports indicate that the 'Demo Store' version may not be vulnerable to the SQL-injection issue.
AFCommerce Shopping Cart is prone to multiple input-validation vulnerabilities. The issues include HTML- and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploits of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
Reports indicate that the 'Demo Store' version is affected by these vulnerabilities; other versions may also be affected.
Vendor reports indicate that the 'Demo Store' version may not be vulnerable to the SQL-injection issue.
Exploit / POC
AFCommerce Shopping Cart Multiple Input Validation Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
AFCommerce Shopping Cart Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
AFCommerce Shopping Cart Multiple Input Validation Vulnerabilities
References:
References:
- AFcommerce Homepage (AFcommerce)
- [[email protected]: Re: AFCommerce Shopping Cart] (Paul Crinigan)
- AFCommerce Shopping Cart ( Sledge)