OSCommerce Product_Info.PHP Denial Of Service Vulnerability
BID:7351
Info
OSCommerce Product_Info.PHP Denial Of Service Vulnerability
| Bugtraq ID: | 7351 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2003 12:00AM |
| Updated: | Apr 15 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Lorenzo Hernandez Garcia-Hierro" <[email protected]>. |
| Vulnerable: |
osCommerce osCommerce 2.2 cvs |
| Not Vulnerable: | |
Discussion
OSCommerce Product_Info.PHP Denial Of Service Vulnerability
It has been reported that an attacker may trigger a denial of service condition in osCommerce application. If malicious URI parameters are passed to several of the osCommerce PHP pages, the mySQL and web server hosting osCommerce reportedly becomes unstable, possibly resulting in a denial of service condition.
It should be noted that although osCommerce version 2.2cvs was reported vulnerable, previous versions may also be affected.
It has been reported that an attacker may trigger a denial of service condition in osCommerce application. If malicious URI parameters are passed to several of the osCommerce PHP pages, the mySQL and web server hosting osCommerce reportedly becomes unstable, possibly resulting in a denial of service condition.
It should be noted that although osCommerce version 2.2cvs was reported vulnerable, previous versions may also be affected.
Exploit / POC
OSCommerce Product_Info.PHP Denial Of Service Vulnerability
The following proof of concept was provided:
product_info.php?products_id=[large amount of random content]
The following proof of concept was provided:
product_info.php?products_id=[large amount of random content]
References
OSCommerce Product_Info.PHP Denial Of Service Vulnerability
References:
References:
- osCommerce Homepage (osCommerce)