osCommerce Multiple Security Vulnerabilities
BID:70159
Info
osCommerce Multiple Security Vulnerabilities
| Bugtraq ID: | 70159 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2014 12:00AM |
| Updated: | Sep 27 2014 12:00AM |
| Credit: | indoushka |
| Vulnerable: |
osCommerce osCommerce 2.3.4 |
| Not Vulnerable: | |
Discussion
osCommerce Multiple Security Vulnerabilities
osCommerce is prone to multiple security vulnerabilities because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, control how the page is rendered to the user, execute arbitrary script code, and override existing hard-coded HTTP parameters which compromises the application.
osCommerce 2.3.4 is vulnerable; other versions may also be affected.
osCommerce is prone to multiple security vulnerabilities because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, control how the page is rendered to the user, execute arbitrary script code, and override existing hard-coded HTTP parameters which compromises the application.
osCommerce 2.3.4 is vulnerable; other versions may also be affected.
Exploit / POC
osCommerce Multiple Security Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.