Hassan Consulting Shopping Cart Arbitrary Command Execution Vulnerability
BID:3308
Info
Hassan Consulting Shopping Cart Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 3308 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0985 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was posted to BugTraq by Alexey Sintsov <[email protected]>. |
| Vulnerable: |
Hassan Consulting Shopping Cart 1.23 |
| Not Vulnerable: | |
Discussion
Hassan Consulting Shopping Cart Arbitrary Command Execution Vulnerability
Hassan Consulting's Shopping Cart is commercial web store software.
Shopping Cart does not filter certain types of user-supplied input from web requests. This makes it possible for a malicious user to submit a request which causes arbitrary commands to be executed on the host (with the privileges of the webserver process). For example, special shell characters like "|" or ";" are treated as valid by Shopping Cart.
Hassan Consulting's Shopping Cart is commercial web store software.
Shopping Cart does not filter certain types of user-supplied input from web requests. This makes it possible for a malicious user to submit a request which causes arbitrary commands to be executed on the host (with the privileges of the webserver process). For example, special shell characters like "|" or ";" are treated as valid by Shopping Cart.
Exploit / POC
Hassan Consulting Shopping Cart Arbitrary Command Execution Vulnerability
This vulnerability can be exploited by submitting a HTTP request froma web browser.
Exploit contributed by SPABAM:
This vulnerability can be exploited by submitting a HTTP request froma web browser.
Exploit contributed by SPABAM:
Solution / Fix
Hassan Consulting Shopping Cart Arbitrary Command Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Hassan Consulting Shopping Cart Arbitrary Command Execution Vulnerability
References:
References:
- Shopping Cart Product Homepage (Hassan Consulting)