Shopizer Multiple Security Vulnerabilities
BID:68483
Info
Shopizer Multiple Security Vulnerabilities
| Bugtraq ID: | 68483 |
| Class: | Unknown |
| CVE: |
CVE-2014-4965 CVE-2014-4964 CVE-2014-4963 CVE-2014-4962 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2014 12:00AM |
| Updated: | Jul 21 2014 12:19AM |
| Credit: | Johannes Dahse and Johannes Greil of SEC Consult Vulnerability Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Shopizer Multiple Security Vulnerabilities
Shopizer is prone to multiple security-bypass vulnerabilities, multiple cross-site scripting vulnerabilities, multiple remote command-injection vulnerabilities, and a cross-site request-forgery vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, execute arbitrary commands in the context of the application, or bypass certain security restrictions.
Shopizer is prone to multiple security-bypass vulnerabilities, multiple cross-site scripting vulnerabilities, multiple remote command-injection vulnerabilities, and a cross-site request-forgery vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, execute arbitrary commands in the context of the application, or bypass certain security restrictions.
Exploit / POC
Shopizer Multiple Security Vulnerabilities
An attacker can use a web browser to exploit some of these issues.
To exploit cross-site scripting or cross-site request forgery vulnerabilities, an attacker must entice an unsuspecting user to follow a malicious URI.
An attacker can use readily available tools to exploit other issues.
The researchers who discovered these issues have created proof-of-concepts. Please see the references for more information.
An attacker can use a web browser to exploit some of these issues.
To exploit cross-site scripting or cross-site request forgery vulnerabilities, an attacker must entice an unsuspecting user to follow a malicious URI.
An attacker can use readily available tools to exploit other issues.
The researchers who discovered these issues have created proof-of-concepts. Please see the references for more information.
Solution / Fix
References
Shopizer Multiple Security Vulnerabilities
References:
References: