ViArt Shop 3.5 Multiple Remote Vulnerabilities
BID:33043
Info
ViArt Shop 3.5 Multiple Remote Vulnerabilities
| Bugtraq ID: | 33043 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6759 CVE-2008-6760 CVE-2008-6765 CVE-2008-6757 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2008 12:00AM |
| Updated: | Jul 06 2016 02:18PM |
| Credit: | Xia Shing Zee |
| Vulnerable: |
ViArt ViArt Shop 3.5 |
| Not Vulnerable: | |
Discussion
ViArt Shop 3.5 Multiple Remote Vulnerabilities
ViArt Shop is prone to multiple remote vulnerabilities:
- Multiple cross-site scripting vulnerabilities
- An information-disclosure vulnerability
- An authentication-bypass vulnerability
An attacker can exploit these issues to execute arbitrary script code, steal cookie-based authentication credentials, obtain sensitive information, or gain unauthorized access to the affected application.
ViArt Shop 3.5 is vulnerable; other versions may also be affected.
ViArt Shop is prone to multiple remote vulnerabilities:
- Multiple cross-site scripting vulnerabilities
- An information-disclosure vulnerability
- An authentication-bypass vulnerability
An attacker can exploit these issues to execute arbitrary script code, steal cookie-based authentication credentials, obtain sensitive information, or gain unauthorized access to the affected application.
ViArt Shop 3.5 is vulnerable; other versions may also be affected.
Exploit / POC
ViArt Shop 3.5 Multiple Remote Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
Solution / Fix
ViArt Shop 3.5 Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ViArt Shop 3.5 Multiple Remote Vulnerabilities
References:
References: