PhPepperShop 'USER_ARTIKEL_HANDLING_AUFRUF.php' Cross-Site Scripting Vulnerability
BID:37707
Info
PhPepperShop 'USER_ARTIKEL_HANDLING_AUFRUF.php' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 37707 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1361 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2010 12:00AM |
| Updated: | Apr 13 2015 09:03PM |
| Credit: | Crux |
| Vulnerable: |
Glarotech PhPepperShop 2.5 |
| Not Vulnerable: | |
Discussion
PhPepperShop 'USER_ARTIKEL_HANDLING_AUFRUF.php' Cross-Site Scripting Vulnerability
PhPepperShop is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
PhPepperShop 2.5 is vulnerable; other versions may also be affected.
PhPepperShop is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
PhPepperShop 2.5 is vulnerable; other versions may also be affected.
Exploit / POC
PhPepperShop 'USER_ARTIKEL_HANDLING_AUFRUF.php' Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
Solution / Fix
PhPepperShop 'USER_ARTIKEL_HANDLING_AUFRUF.php' Cross-Site Scripting Vulnerability
Solution:
Fixes are available. Please see the references for more information.
Glarotech PhPepperShop 2.5
Solution:
Fixes are available. Please see the references for more information.
Glarotech PhPepperShop 2.5
-
Glarotech sec_hotfix_v251_18012009.zip
http://www.phpeppershop.com/phpeppershop_files/sec_hotfix_v251_1801200 9.zip
References
PhPepperShop 'USER_ARTIKEL_HANDLING_AUFRUF.php' Cross-Site Scripting Vulnerability
References:
References:
- PhPepperShop Homepage (Glarotech)