IXXO Cart 'parent' Parameter SQL Injection Vulnerability
BID:35810
Info
IXXO Cart 'parent' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 35810 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2009 12:00AM |
| Updated: | Jul 09 2010 04:58PM |
| Credit: | SmOk3 |
| Vulnerable: |
IXXO Cart 3.9.6.0 IXXO Cart 0 |
| Not Vulnerable: | |
Discussion
IXXO Cart 'parent' Parameter SQL Injection Vulnerability
IXXO Cart is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
IXXO Cart is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
IXXO Cart 'parent' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following examples are available:
parent=1%27)%20order%20by%203/*
http://site.com/ixxo/index.php?p=catalog&parent=[SQLI]
Attackers can use a browser to exploit this issue.
The following examples are available:
parent=1%27)%20order%20by%203/*
http://site.com/ixxo/index.php?p=catalog&parent=[SQLI]
Solution / Fix
IXXO Cart 'parent' Parameter SQL Injection Vulnerability
Solution:
Reports indicate that IXXO Cart 3.9.6.1 did not properly address this issue.
Solution:
Reports indicate that IXXO Cart 3.9.6.1 did not properly address this issue.
References
IXXO Cart 'parent' Parameter SQL Injection Vulnerability
References:
References: