cpCommerce Security Bypass and SQL Injection Vulnerabilities
BID:32549
Info
cpCommerce Security Bypass and SQL Injection Vulnerabilities
| Bugtraq ID: | 32549 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2008 12:00AM |
| Updated: | Dec 01 2008 11:53PM |
| Credit: | girex |
| Vulnerable: |
cpCommerce cpCommerce 1.2.6 |
| Not Vulnerable: |
cpCommerce cpCommerce 1.2.7 |
Discussion
cpCommerce Security Bypass and SQL Injection Vulnerabilities
cpCommerce is prone to a security-bypass vulnerability and an SQL-injection issue.
Exploiting the security-bypass issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions. The attacker can exploit the SQL-injection issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database. This may compromise the application and may aid in further attacks.
cpCommerce 1.2.6 is vulnerable; other versions may also be affected.
cpCommerce is prone to a security-bypass vulnerability and an SQL-injection issue.
Exploiting the security-bypass issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions. The attacker can exploit the SQL-injection issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database. This may compromise the application and may aid in further attacks.
cpCommerce 1.2.6 is vulnerable; other versions may also be affected.
Exploit / POC
cpCommerce Security Bypass and SQL Injection Vulnerabilities
Attackers can exploit the issues via a browser.
The following example URIs are available:
http://www.example.com/index.php/email/%27%20OR%20id_account=1%23/?action=login&submit=Login&returnurl=index.php
http://www.example.com/index.php/key/value/
Attackers can exploit the issues via a browser.
The following example URIs are available:
http://www.example.com/index.php/email/%27%20OR%20id_account=1%23/?action=login&submit=Login&returnurl=index.php
http://www.example.com/index.php/key/value/
Solution / Fix
cpCommerce Security Bypass and SQL Injection Vulnerabilities
Solution:
The vendor has released an update to address the issues. Please see the references for more information.
cpCommerce cpCommerce 1.2.6
Solution:
The vendor has released an update to address the issues. Please see the references for more information.
cpCommerce cpCommerce 1.2.6
-
cpCommerce v1.2.7.patch
http://cpcommerce.cpradio.org/downloads.php?action=download.patch&v=v1 .2.7
References
cpCommerce Security Bypass and SQL Injection Vulnerabilities
References:
References:
- cpCommerce Homepage (cpCommerce)