Qualiteam X-Cart CMPI.PHP Arbitrary Variable Overwrite Vulnerability
BID:20108
CVE-2006-4904 |Info
Qualiteam X-Cart CMPI.PHP Arbitrary Variable Overwrite Vulnerability
| Bugtraq ID: | 20108 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2006 12:00AM |
| Updated: | Sep 20 2006 09:16PM |
| Credit: | James Bercegay of the GulfTech Security Research Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
Qualiteam X-Cart 4.1.3 |
| Not Vulnerable: | |
Discussion
Qualiteam X-Cart CMPI.PHP Arbitrary Variable Overwrite Vulnerability
Qualiteam X-Cart is prone to a vulnerability that permits an attacker to overwrite arbitrary variables. This issue is due to a design flaw in handling HTTP POST variables.
An attacker can exploit this issue to overwrite the arbitrary variables with arbitrary input. Through control of the global variables, the attacker may be able to perform remote and local file-include, cross-site scripting, SQL-injection, and other attacks. This may facilitate a complete remote compromise of the application.
Qualiteam X-Cart is prone to a vulnerability that permits an attacker to overwrite arbitrary variables. This issue is due to a design flaw in handling HTTP POST variables.
An attacker can exploit this issue to overwrite the arbitrary variables with arbitrary input. Through control of the global variables, the attacker may be able to perform remote and local file-include, cross-site scripting, SQL-injection, and other attacks. This may facilitate a complete remote compromise of the application.
Exploit / POC
Qualiteam X-Cart CMPI.PHP Arbitrary Variable Overwrite Vulnerability
Attackers may exploit this issue with a web browser.
Attackers may exploit this issue with a web browser.
Solution / Fix
Qualiteam X-Cart CMPI.PHP Arbitrary Variable Overwrite Vulnerability
Solution:
The vendor has released an update addressing this issue; please contact the vendor for details.
Solution:
The vendor has released an update addressing this issue; please contact the vendor for details.
References
Qualiteam X-Cart CMPI.PHP Arbitrary Variable Overwrite Vulnerability
References:
References:
- X-Cart Arbitrary Code Execution (Gulftech)
- X-Cart Web Site (X-Cart)