FreeWebshop 2.2.9 R2 Multiple Remote Vulnerabilities
BID:37513
Info
FreeWebshop 2.2.9 R2 Multiple Remote Vulnerabilities
| Bugtraq ID: | 37513 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2009 12:00AM |
| Updated: | Dec 30 2009 07:52PM |
| Credit: | Akita Software Security |
| Vulnerable: |
FreeWebshop FreeWebshop 2.2.9 R2 |
| Not Vulnerable: | |
Discussion
FreeWebshop 2.2.9 R2 Multiple Remote Vulnerabilities
FreeWebshop is prone to multiple remote vulnerabilities:
1. A security vulnerability that may allow attackers to spoof HTTP headers.
2. A security vulnerability involving the handling of sessions.
3. A security vulnerability that may allow attackers to brute-force passwords.
4. A security-bypass vulnerability.
5. An SQL-injection vulnerability.
6. A directory-traversal vulnerability.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities, gain unauthorized access to the affected application, and obtain sensitive information.
FreeWebshop.org 2.2.9 R2 is vulnerable; other versions may also be affected.
FreeWebshop is prone to multiple remote vulnerabilities:
1. A security vulnerability that may allow attackers to spoof HTTP headers.
2. A security vulnerability involving the handling of sessions.
3. A security vulnerability that may allow attackers to brute-force passwords.
4. A security-bypass vulnerability.
5. An SQL-injection vulnerability.
6. A directory-traversal vulnerability.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities, gain unauthorized access to the affected application, and obtain sensitive information.
FreeWebshop.org 2.2.9 R2 is vulnerable; other versions may also be affected.
Exploit / POC
FreeWebshop 2.2.9 R2 Multiple Remote Vulnerabilities
An attacker can exploit these issues via a browser.
The following exploits are available:
An attacker can exploit these issues via a browser.
The following exploits are available:
Solution / Fix
FreeWebshop 2.2.9 R2 Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FreeWebshop 2.2.9 R2 Multiple Remote Vulnerabilities
References:
References:
- FreeWebshop Homepage (FreeWebShop)
- FreeWebshop.org: multiple vulnerabilities (Akita Software Security
)