Comersus Cart User Email and User Password Unauthorized Access Vulnerability
BID:33217
Info
Comersus Cart User Email and User Password Unauthorized Access Vulnerability
| Bugtraq ID: | 33217 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2009 12:00AM |
| Updated: | Jan 15 2009 08:52PM |
| Credit: | ajann |
| Vulnerable: |
Comersus Open Technologies Comersus Cart 6 |
| Not Vulnerable: | |
Discussion
Comersus Cart User Email and User Password Unauthorized Access Vulnerability
Comersus Cart is prone to a vulnerability that can result in unauthorized access.
An attacker can exploit this issue to gain unauthorized access to the affected application. Successfully exploiting this issue may compromise the application.
Comersus Cart 6 is vulnerable; other versions may also be affected.
Comersus Cart is prone to a vulnerability that can result in unauthorized access.
An attacker can exploit this issue to gain unauthorized access to the affected application. Successfully exploiting this issue may compromise the application.
Comersus Cart 6 is vulnerable; other versions may also be affected.
Exploit / POC
Comersus Cart User Email and User Password Unauthorized Access Vulnerability
Attackers can exploit this issue using a browser.
The following exploit code is available:
Attackers can exploit this issue using a browser.
The following exploit code is available:
Solution / Fix
Comersus Cart User Email and User Password Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Comersus Cart User Email and User Password Unauthorized Access Vulnerability
References:
References:
- Comersus Cart (Comersus Open Technologies)
- Comersus Shopping Cart <= v6 Remote User Pass Exploit ([email protected] )