CubeCart Multiple Cross Site Scripting and SQL Injection Vulnerabilities
BID:43114
Info
CubeCart Multiple Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 43114 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-4903 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2010 12:00AM |
| Updated: | Oct 11 2011 09:00PM |
| Credit: | Bogdan Calin |
| Vulnerable: |
CubeCart CubeCart 4.3.3 |
| Not Vulnerable: | |
Discussion
CubeCart Multiple Cross Site Scripting and SQL Injection Vulnerabilities
CubeCart is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
CubeCart 4.3.3 is vulnerable; other versions may also be affected.
CubeCart is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
CubeCart 4.3.3 is vulnerable; other versions may also be affected.
Exploit / POC
CubeCart Multiple Cross Site Scripting and SQL Injection Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
CubeCart Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
Reports indicate that updates are available; Symantec has not verified this. Please see the references for more information.
Solution:
Reports indicate that updates are available; Symantec has not verified this. Please see the references for more information.
References
CubeCart Multiple Cross Site Scripting and SQL Injection Vulnerabilities
References:
References:
- CubeCart Homepage (CubeCart)
- SQL Injection and XSS vulnerabilities in CubeCart version 4.3.3 (Bogdan Calin
)