Interspire Shopping Cart Cookie Authentication Bypass Vulnerability
BID:33212
Info
Interspire Shopping Cart Cookie Authentication Bypass Vulnerability
| Bugtraq ID: | 33212 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2009 12:00AM |
| Updated: | Jan 15 2009 08:22PM |
| Credit: | Truong Van Tri and Blue Moon Consulting |
| Vulnerable: |
Interspire Shopping Cart 4.0.1 Interspire Shopping Cart 0 |
| Not Vulnerable: |
Interspire Shopping Cart 4.0.2 |
Discussion
Interspire Shopping Cart Cookie Authentication Bypass Vulnerability
Interspire Shopping Cart is prone to an authentication-bypass vulnerability because it fails to adequately verify user credentials when setting cookie-based authentication tokens.
Attackers can exploit this issue to gain unauthorized access to the affected application, which may aid in further attacks.
Interspire Shopping Cart 4.0.1 is vulnerable; other versions may also be affected.
Interspire Shopping Cart is prone to an authentication-bypass vulnerability because it fails to adequately verify user credentials when setting cookie-based authentication tokens.
Attackers can exploit this issue to gain unauthorized access to the affected application, which may aid in further attacks.
Interspire Shopping Cart 4.0.1 is vulnerable; other versions may also be affected.
Exploit / POC
Interspire Shopping Cart Cookie Authentication Bypass Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Interspire Shopping Cart Cookie Authentication Bypass Vulnerability
Solution:
This issue is reported to be fixed in Interspire Shopping Cart 4.0.2; please see the references for more information.
Solution:
This issue is reported to be fixed in Interspire Shopping Cart 4.0.2; please see the references for more information.
References
Interspire Shopping Cart Cookie Authentication Bypass Vulnerability
References:
References: