Comersus Cart Multiple Input Validation Vulnerabilities
BID:24562
Info
Comersus Cart Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 24562 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3323 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Discovery of this vulnerability is credited to DoZ. |
| Vulnerable: |
Comersus Open Technologies Comersus Cart 7.0.7 |
| Not Vulnerable: | |
Discussion
Comersus Cart Multiple Input Validation Vulnerabilities
Comersus Cart is affected by multiple input validation vulnerabilities.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
The attacker may also leverage this issue to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Comersus Cart 7.0.7 is vulnerable; other versions may also be affected.
Comersus Cart is affected by multiple input validation vulnerabilities.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
The attacker may also leverage this issue to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Comersus Cart 7.0.7 is vulnerable; other versions may also be affected.
Exploit / POC
Comersus Cart Multiple Input Validation Vulnerabilities
To exploit the cross-site scripting issues, an attacker must entice an unsuspecting victim into following a malicious URI. The attacker can use a browser to exploit the SQL-injection issue.
The following example URI is available:
http://www.example.com/comersus_message.asp?message=<script>alert('Bl@ckbe@rD is not dead yet')</script>[Peace xD ]
The following proofs of concept have been provided:
To exploit the cross-site scripting issues, an attacker must entice an unsuspecting victim into following a malicious URI. The attacker can use a browser to exploit the SQL-injection issue.
The following example URI is available:
http://www.example.com/comersus_message.asp?message=<script>alert('Bl@ckbe@rD is not dead yet')</script>[Peace xD ]
The following proofs of concept have been provided:
Solution / Fix
Comersus Cart Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Comersus Cart Multiple Input Validation Vulnerabilities
References:
References:
- Comersus Cart Homepage (Comersus Open Technologies)
- Comersus Shop Cart 7.07 SQL Injection & XSS ([email protected])