Zen Cart Session Fixation Vulnerability
BID:24768
Info
Zen Cart Session Fixation Vulnerability
| Bugtraq ID: | 24768 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2007 12:00AM |
| Updated: | Jul 05 2007 11:47PM |
| Credit: | Tomaz Bratusa is credited with the discovery of this vulnerability. |
| Vulnerable: |
Zen Cart Zen Cart 1.3.7 |
| Not Vulnerable: |
Zen Cart Zen Cart 1.3.7-full-patched 0 |
Discussion
Zen Cart Session Fixation Vulnerability
Zen Cart is prone to a session-fixation vulnerability. This issue stems from a design error in the application.
When the unsuspecting victim logs in, an attacker can hijack the session and gain unauthorized access to the affected application.
Zen Cart 1.3.7 is vulnerable to this issue; other versions may also be vulnerable.
Zen Cart is prone to a session-fixation vulnerability. This issue stems from a design error in the application.
When the unsuspecting victim logs in, an attacker can hijack the session and gain unauthorized access to the affected application.
Zen Cart 1.3.7 is vulnerable to this issue; other versions may also be vulnerable.
Exploit / POC
Zen Cart Session Fixation Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI. The attacker can then use a browser to gain unauthorized access to a vulnerable application.
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI. The attacker can then use a browser to gain unauthorized access to a vulnerable application.
Solution / Fix
Zen Cart Session Fixation Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Zen Cart Zen Cart 1.3.7
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Zen Cart Zen Cart 1.3.7
-
Zen Cart Zen-cart-v1.3.7-full-patched-07012007.zip
http://downloads.sourceforge.net/zencart/zen-cart-v1.3.7-full-patched- 07012007.zip?modtime=1183311019&big_mirror=0
References
Zen Cart Session Fixation Vulnerability
References:
References:
- [ 1702720 ] Authorisation Pending Setting 1 Breaks Logout/Login (Zen Cart)
- Vendor Home Page (Zen Cart)