Multiple E-Commerce Products SQL Injection Vulnerability
BID:55046
Info
Multiple E-Commerce Products SQL Injection Vulnerability
| Bugtraq ID: | 55046 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2012 12:00AM |
| Updated: | Jun 12 2012 12:00AM |
| Credit: | Ralf Zimmermann |
| Vulnerable: |
xt:Commerce xt:Commerce 3.04 Sp2.1 xt:Commerce xt:Commerce 3.04 Gambio Gambio 2.0.10 SP1.4 commerce-seo commerce:SEO 2.1 |
| Not Vulnerable: |
commerce-seo commerce:SEO 2.2 |
Discussion
Multiple E-Commerce Products SQL Injection Vulnerability
Multiple e-commerce products including xt:Commerce, commerce:seo, and Gambio are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are vulnerable:
xt:Commerce 3.04 SP2.1 and prior versions
commerce:SEO 2.1 and prior versions
Gambio 2.0.10 SP1.4 and prior versions
Multiple e-commerce products including xt:Commerce, commerce:seo, and Gambio are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are vulnerable:
xt:Commerce 3.04 SP2.1 and prior versions
commerce:SEO 2.1 and prior versions
Gambio 2.0.10 SP1.4 and prior versions
Exploit / POC
Multiple E-Commerce Products SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
http://www.example.com/xtc_304SP21/admin/backup.php /IF((SELECT%20ASCII(SUBSTR(customers_email_address,1,1))%20FROM%20customers%20WHERE%20customers_id=1)=97,BENCHMARK(100000000,MD5(1)),1)--%20.php?
Attackers can use a browser to exploit this issue.
http://www.example.com/xtc_304SP21/admin/backup.php /IF((SELECT%20ASCII(SUBSTR(customers_email_address,1,1))%20FROM%20customers%20WHERE%20customers_id=1)=97,BENCHMARK(100000000,MD5(1)),1)--%20.php?
Solution / Fix
Multiple E-Commerce Products SQL Injection Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
Multiple E-Commerce Products SQL Injection Vulnerability
References:
References:
- An important security update for all xtc forks (xtc)
- Gambio Homepage (Gambio)
- xt:Commerce Homepage (xt:Commerce GmbH / xt:Commerce International Ltd.)
- commerce-SEO Homepage (SEOCommerce)