Zen Cart 1.3.9f and 1.3.9h Multiple Input Validation Vulnerabilities
BID:47935
Info
Zen Cart 1.3.9f and 1.3.9h Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 47935 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2011 12:00AM |
| Updated: | May 18 2011 12:00AM |
| Credit: | Dr. Alberto Fontanella |
| Vulnerable: |
Zen Cart Zen Cart 1.3.9h Zen Cart Zen Cart 1.3.9f |
| Not Vulnerable: | |
Discussion
Zen Cart 1.3.9f and 1.3.9h Multiple Input Validation Vulnerabilities
Zen Cart is prone to an arbitrary-file-upload vulnerability, a cross-site scripting vulnerability, and multiple HTML-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Attackers can exploit these issues to upload and execute arbitrary PHP code in the context of the webserver process, steal cookie-based authentication information, execute arbitrary client-side scripts in the context of the browser, and obtain sensitive information. Other attacks are also possible.
Zen Cart 1.3.9f and 1.3.9h are vulnerable; other versions may also be affected.
Zen Cart is prone to an arbitrary-file-upload vulnerability, a cross-site scripting vulnerability, and multiple HTML-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Attackers can exploit these issues to upload and execute arbitrary PHP code in the context of the webserver process, steal cookie-based authentication information, execute arbitrary client-side scripts in the context of the browser, and obtain sensitive information. Other attacks are also possible.
Zen Cart 1.3.9f and 1.3.9h are vulnerable; other versions may also be affected.
References
Zen Cart 1.3.9f and 1.3.9h Multiple Input Validation Vulnerabilities
References:
References:
- Zen Cart Homepage (Zen Ventures)