EC-CUBE SQL Injection and Cross-Site Scripting Vulnerabilities
BID:31509
Info
EC-CUBE SQL Injection and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 31509 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4534 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | Yuya Yoshida, Naruhisa Tadokoro and Masako Oono |
| Vulnerable: |
EC-CUBE EC-CUBE Community Edition Nightly-Build r17623 EC-CUBE EC-CUBE Community Edition Nightly-Build r17336 EC-CUBE EC-CUBE Community Edition Nightly-Build r17319 EC-CUBE EC-CUBE Community Edition 1.3.4 EC-CUBE EC-CUBE 1.4.6 EC-CUBE EC-CUBE 1.0 EC-CUBE EC-CUBE 2.3.0-rc1 EC-CUBE EC-CUBE 2.2.0-beta EC-CUBE EC-CUBE 2.1.2a EC-CUBE EC-CUBE 2.1.1-beta EC-CUBE EC-CUBE 1.5.0-beta EC-CUBE EC-CUBE 1.0.1a beta |
| Not Vulnerable: |
EC-CUBE EC-CUBE Community Edition 1.3.5 EC-CUBE EC-CUBE 2.3 EC-CUBE EC-CUBE 1.4.7 |
Discussion
EC-CUBE SQL Injection and Cross-Site Scripting Vulnerabilities
EC-CUBE is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The attacker may exploit the SQL-injection issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following versions are vulnerable:
EC-CUBE 2.1.2a and earlier
EC-CUBE 2.3.0-rc1 and earlier
EC-CUBE 2.2.0-beta and earlier
EC-CUBE 2.1.1-beta and earlier
EC-CUBE 1.4.6 and earlier
EC-CUBE 1.5.0-beta and earlier
EC-CUBE Community Edition 1.3.4 and earlier
EC-CUBE Community Edition Nightly-Build r17319 and earlier
EC-CUBE Community Edition Nightly-Build r17336 and earlier
EC-CUBE Community Edition Nightly-Build r17623 and earlier
EC-CUBE is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The attacker may exploit the SQL-injection issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following versions are vulnerable:
EC-CUBE 2.1.2a and earlier
EC-CUBE 2.3.0-rc1 and earlier
EC-CUBE 2.2.0-beta and earlier
EC-CUBE 2.1.1-beta and earlier
EC-CUBE 1.4.6 and earlier
EC-CUBE 1.5.0-beta and earlier
EC-CUBE Community Edition 1.3.4 and earlier
EC-CUBE Community Edition Nightly-Build r17319 and earlier
EC-CUBE Community Edition Nightly-Build r17336 and earlier
EC-CUBE Community Edition Nightly-Build r17623 and earlier
Exploit / POC
EC-CUBE SQL Injection and Cross-Site Scripting Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
EC-CUBE SQL Injection and Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
EC-CUBE SQL Injection and Cross-Site Scripting Vulnerabilities
References:
References: