CS-Cart 'reward_points.post.php' SQL Injection Vulnerability
BID:35936
Info
CS-Cart 'reward_points.post.php' SQL Injection Vulnerability
| Bugtraq ID: | 35936 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2579 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2009 12:00AM |
| Updated: | Aug 21 2009 03:57PM |
| Credit: | Ryan Dewhurst |
| Vulnerable: |
CS-Cart CS-Cart 2.0.5 CS-Cart CS-Cart 2.0 Beta 3 |
| Not Vulnerable: |
CS-Cart CS-Cart 2.0.6 |
Discussion
CS-Cart 'reward_points.post.php' SQL Injection Vulnerability
CS-Cart is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to CS-Cart 2.0.6 are vulnerable.
CS-Cart is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to CS-Cart 2.0.6 are vulnerable.
Exploit / POC
CS-Cart 'reward_points.post.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?dispatch=reward_points.userlog&result_ids=pagination_contents&sort_by=timestamp&sort_order='
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?dispatch=reward_points.userlog&result_ids=pagination_contents&sort_by=timestamp&sort_order='
Solution / Fix
CS-Cart 'reward_points.post.php' SQL Injection Vulnerability
Solution:
Updates are reported to be available; please see the references for more information.
Solution:
Updates are reported to be available; please see the references for more information.
References
CS-Cart 'reward_points.post.php' SQL Injection Vulnerability
References:
References:
- Changelog (2.0.5 - 2.0.6) (CS-Cart)
- CS-Cart Homepage (CS-Cart)
- [BONSAI] SQL Injection in CS-Cart (Bonsai - Information Security
)