Conkurent PHPMyCart Cross Site Scripting and Authentication Bypass Vulnerabilities
BID:37553
Info
Conkurent PHPMyCart Cross Site Scripting and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 37553 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 2009 12:00AM |
| Updated: | Dec 31 2009 09:12PM |
| Credit: | indoushka |
| Vulnerable: |
Conkurent PHPMyCart 1.3 |
| Not Vulnerable: | |
Discussion
Conkurent PHPMyCart Cross Site Scripting and Authentication Bypass Vulnerabilities
Conkurent PHPMyCart is prone to a cross-site scripting vulnerability and an authentication-bypass vulnerability.
An attacker may leverage these issues to gain unauthorized access to the affected application and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
PHPMyCart 1.3 is vulnerable; other versions may also be affected.
Conkurent PHPMyCart is prone to a cross-site scripting vulnerability and an authentication-bypass vulnerability.
An attacker may leverage these issues to gain unauthorized access to the affected application and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
PHPMyCart 1.3 is vulnerable; other versions may also be affected.
Exploit / POC
Conkurent PHPMyCart Cross Site Scripting and Authentication Bypass Vulnerabilities
An attacker can exploit these issues using a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
An attacker can exploit these issues using a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
Solution / Fix
Conkurent PHPMyCart Cross Site Scripting and Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Conkurent PHPMyCart Cross Site Scripting and Authentication Bypass Vulnerabilities
References:
References:
- PHPMyCart Homepage (Conkurent)