Zen Cart Multiple Input Validation Vulnerabilities
BID:43628
Info
Zen Cart Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 43628 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2010 12:00AM |
| Updated: | Oct 01 2010 12:00AM |
| Credit: | Gjoko Krstic |
| Vulnerable: |
Zen Cart Zen Cart 1.3.9f |
| Not Vulnerable: |
Zen Cart Zen Cart 1.3.9g |
Discussion
Zen Cart Multiple Input Validation Vulnerabilities
Zen Cart is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input. These vulnerabilities include local file-include, SQL-injection, and HTML-injection issues.
Exploiting these issues can allow attacker-supplied HTML and script code to run in the context of the affected browser, allowing attackers to steal cookie-based authentication credentials, view local files within the context of the webserver, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Zen Cart v1.3.9f is vulnerable; other versions may also be affected.
Zen Cart is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input. These vulnerabilities include local file-include, SQL-injection, and HTML-injection issues.
Exploiting these issues can allow attacker-supplied HTML and script code to run in the context of the affected browser, allowing attackers to steal cookie-based authentication credentials, view local files within the context of the webserver, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Zen Cart v1.3.9f is vulnerable; other versions may also be affected.
Exploit / POC
Zen Cart Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user to visit a malicious URI.
The following example URIs are available:
SQL Injection:
http://www.example.com/admin/options_name_manager.php?option_page=1&option_order_by=/ [SQLi]
Local File Include:
http://www.example.com/index.php?typefilter=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fboot.ini%00
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user to visit a malicious URI.
The following example URIs are available:
SQL Injection:
http://www.example.com/admin/options_name_manager.php?option_page=1&option_order_by=/ [SQLi]
Local File Include:
http://www.example.com/index.php?typefilter=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fboot.ini%00
Solution / Fix
Zen Cart Multiple Input Validation Vulnerabilities
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
Zen Cart Multiple Input Validation Vulnerabilities
References:
References:
- Zen Cart Homepage (Zen Cart)
- Zen Cart v1.3.9f (typefilter) Local File Inclusion Vulnerability (Zen Cart)
- Zen Cart v1.3.9f Multiple Remote Vulnerabilities (Zen Cart)