Eazy Cart Multiple Input Validation and Authentication Bypass Vulnerabilities
BID:20423
Info
Eazy Cart Multiple Input Validation and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 20423 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2006 12:00AM |
| Updated: | Oct 11 2006 06:54PM |
| Credit: | Mayhemic Labs Security is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Eazy Cart Eazy Cart 0 |
| Not Vulnerable: | |
Discussion
Eazy Cart Multiple Input Validation and Authentication Bypass Vulnerabilities
Eazy Cart is prone to multiple input-validation and authentication-bypass vulnerabilities. These include data-injection, cross-site scripting, and authentication-bypass issues because the application fails to properly sanitize user-supplied input or to control access to administrative functions.
A successful exploit of these vulnerabilities could allow an attacker to modify prices and other values when ordering products, steal cookie-based authentication credentials from legitimate users of the site, or even bypass authentication requirements. Other attacks are also possible.
Eazy Cart is prone to multiple input-validation and authentication-bypass vulnerabilities. These include data-injection, cross-site scripting, and authentication-bypass issues because the application fails to properly sanitize user-supplied input or to control access to administrative functions.
A successful exploit of these vulnerabilities could allow an attacker to modify prices and other values when ordering products, steal cookie-based authentication credentials from legitimate users of the site, or even bypass authentication requirements. Other attacks are also possible.
Exploit / POC
Eazy Cart Multiple Input Validation and Authentication Bypass Vulnerabilities
Attackers can exploit these issues via a web client or by tricking an unsuspecting user into following a malicious URI.
Attackers can exploit these issues via a web client or by tricking an unsuspecting user into following a malicious URI.
Solution / Fix
Eazy Cart Multiple Input Validation and Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Eazy Cart Multiple Input Validation and Authentication Bypass Vulnerabilities
References:
References:
- Eazy Cart Homepage (Eazy Cart)
- MHL-2006-001 - Eazy Cart Multiple Security Issues (Mayhemic Labs)