OpenCart 'order' Parameter SQL Injection Vulnerability
BID:34121
Info
OpenCart 'order' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 34121 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2009 12:00AM |
| Updated: | Mar 16 2009 06:36PM |
| Credit: | nGenuity Information Services |
| Vulnerable: |
OpenCart OpenCart 1.1.8 |
| Not Vulnerable: |
OpenCart OpenCart 1.1.9 |
Discussion
OpenCart 'order' Parameter SQL Injection Vulnerability
OpenCart is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OpenCart 1.1.8 is vulnerable; other versions may also be affected.
OpenCart is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OpenCart 1.1.8 is vulnerable; other versions may also be affected.
Exploit / POC
OpenCart 'order' Parameter SQL Injection Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
OpenCart 'order' Parameter SQL Injection Vulnerability
Solution:
Reports indicate that the vendor has released an update, but Symantec was unable to confirm this information. Please see the references and contact the vendor for more information.
Solution:
Reports indicate that the vendor has released an update, but Symantec was unable to confirm this information. Please see the references and contact the vendor for more information.
References
OpenCart 'order' Parameter SQL Injection Vulnerability
References:
References:
- OpenCart Homepage (OpenCart)
- NGENUITY-2009-005 OpenCart Order By Blind SQL Injection (Adam Baldwin
) - NGENUITY-2009-005 OpenCart Order By Blind SQL Injection (nGenuity Information Services)