Multiple EtoShop Products Login Parameters SQL Injection Vulnerabilities
BID:33930
Info
Multiple EtoShop Products Login Parameters SQL Injection Vulnerabilities
| Bugtraq ID: | 33930 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2009 12:00AM |
| Updated: | Jul 14 2011 07:20AM |
| Credit: | Pouya Server |
| Vulnerable: |
EtoShop Webstore Creator 5.0 EtoShop Classifieds Creator 2.0 EtoShop C2C Reverse Auction Creator 2.0 EtoShop C2C Forward Auction Creator 2.0 EtoShop B2C StoreBuilder Designer 2.0 EtoShop B2C Online Shop Creator 4.0 EtoShop B2B Reverse Auction Creator 2.0 EtoShop B2B Horizontal Marketplace Creator 2.0 EtoShop B2B Forward Auction Creator 2.0 |
| Not Vulnerable: | |
Discussion
Multiple EtoShop Products Login Parameters SQL Injection Vulnerabilities
Multiple EtoShop products are prone to SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following applications are vulnerable:
B2C StoreBuilder Designer 2.0
B2C Online Shop Creator 4.0
Webstore Creator 5.0
B2B Horizontal Marketplace Creator 2.0
B2B Forward Auction Creator 2.0
C2C Reverse Auction Creator 2.0
B2B Reverse Auction Creator 2.0
C2C Forward Auction Creator 2.0
Multiple EtoShop products are prone to SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following applications are vulnerable:
B2C StoreBuilder Designer 2.0
B2C Online Shop Creator 4.0
Webstore Creator 5.0
B2B Horizontal Marketplace Creator 2.0
B2B Forward Auction Creator 2.0
C2C Reverse Auction Creator 2.0
B2B Reverse Auction Creator 2.0
C2C Forward Auction Creator 2.0
Exploit / POC
Multiple EtoShop Products Login Parameters SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Multiple EtoShop Products Login Parameters SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple EtoShop Products Login Parameters SQL Injection Vulnerabilities
References:
References:
- EtoShop Homepage (EtoShop)