Cart32 Hidden Form Field Manipulation Vulnerability
BID:6178
Info
Cart32 Hidden Form Field Manipulation Vulnerability
| Bugtraq ID: | 6178 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2002 12:00AM |
| Updated: | Nov 13 2002 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
McMurtrey/Whitaker & Associates Cart32 4.4 McMurtrey/Whitaker & Associates Cart32 3.5 a Build 710 McMurtrey/Whitaker & Associates Cart32 3.5 a McMurtrey/Whitaker & Associates Cart32 3.5 Build 619 McMurtrey/Whitaker & Associates Cart32 3.5 McMurtrey/Whitaker & Associates Cart32 3.1 McMurtrey/Whitaker & Associates Cart32 3.0 McMurtrey/Whitaker & Associates Cart32 2.6 McMurtrey/Whitaker & Associates Cart32 2.5 a |
| Not Vulnerable: | |
Discussion
Cart32 Hidden Form Field Manipulation Vulnerability
Cart32 does not sufficiently validate information provided in hidden form fields. As a result, an attacker may submit a custom form containing arbitrary values for hidden form fields. This may be used to manipulate prices for items purchased through the Cart32 shopping system. It may also be possible to manipulate other types of data contained in hidden form fields.
Cart32 does not sufficiently validate information provided in hidden form fields. As a result, an attacker may submit a custom form containing arbitrary values for hidden form fields. This may be used to manipulate prices for items purchased through the Cart32 shopping system. It may also be possible to manipulate other types of data contained in hidden form fields.
Solution / Fix
Cart32 Hidden Form Field Manipulation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cart32 Hidden Form Field Manipulation Vulnerability
References:
References: