Avactis Shopping Cart Security Bypass and HTML Injection Vulnerabilities
BID:48438
Info
Avactis Shopping Cart Security Bypass and HTML Injection Vulnerabilities
| Bugtraq ID: | 48438 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2011 12:00AM |
| Updated: | Jun 24 2011 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Pentasoft Avactis Shopping Cart 1.9.1 Pentasoft Avactis Shopping Cart 1.8.1 Pentasoft Avactis Shopping Cart 1.8 Pentasoft Avactis Shopping Cart 2.1.0 |
| Not Vulnerable: |
Pentasoft Avactis Shopping Cart 2.1.1 |
Discussion
Avactis Shopping Cart Security Bypass and HTML Injection Vulnerabilities
Avactis Shopping Cart is prone to a security-bypass vulnerability and an HTML-injection vulnerability because it fails to properly validate user-supplied input.
An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
The attacker may leverage the security-bypass issue to bypass certain security restrictions and perform unauthorized actions in the affected application.
Versions prior to Avactis Shopping Cart 2.1.1 are vulnerable.
Avactis Shopping Cart is prone to a security-bypass vulnerability and an HTML-injection vulnerability because it fails to properly validate user-supplied input.
An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
The attacker may leverage the security-bypass issue to bypass certain security restrictions and perform unauthorized actions in the affected application.
Versions prior to Avactis Shopping Cart 2.1.1 are vulnerable.
Exploit / POC
Avactis Shopping Cart Security Bypass and HTML Injection Vulnerabilities
Attackers can use a browser to exploit the issues.
Attackers can use a browser to exploit the issues.
Solution / Fix
Avactis Shopping Cart Security Bypass and HTML Injection Vulnerabilities
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
Avactis Shopping Cart Security Bypass and HTML Injection Vulnerabilities
References:
References:
- Avactis Shopping Cart Homepage (Pentasoft)
- Jun 22, 2011 - Changelog for version 2.1.1 (Pentasoft)