FishCart Olst Parameter SQL Injection Vulnerability
BID:22166
Info
FishCart Olst Parameter SQL Injection Vulnerability
| Bugtraq ID: | 22166 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2007 12:00AM |
| Updated: | Jan 25 2007 04:24PM |
| Credit: | laurent gaffie is credited with the discovery of this vulnerability. |
| Vulnerable: |
FishNet FishCart 3.1 FishNet FishCart 3.0.7 b FishNet FishCart 2.21 FishNet FishCart 1.90 |
| Not Vulnerable: |
FishNet FishCart current CVS |
Discussion
FishCart Olst Parameter SQL Injection Vulnerability
FishCart is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
FishCart is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
FishCart Olst Parameter SQL Injection Vulnerability
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/uds/display.php?cartid=200701210157208&zid=1&lid=1&olimit=5&cat=&key1=&nlst=y&olst='[sql]
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/uds/display.php?cartid=200701210157208&zid=1&lid=1&olimit=5&cat=&key1=&nlst=y&olst='[sql]
Solution / Fix
FishCart Olst Parameter SQL Injection Vulnerability
Solution:
To address this issue, the vendor released an update through their CVS repository. Please contact the vendor for information on how to obtain and apply this update.
Solution:
To address this issue, the vendor released an update through their CVS repository. Please contact the vendor for information on how to obtain and apply this update.
References
FishCart Olst Parameter SQL Injection Vulnerability
References:
References: