OSCommerce Authentication Bypass Vulnerability
BID:7357
Info
OSCommerce Authentication Bypass Vulnerability
| Bugtraq ID: | 7357 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2003 12:00AM |
| Updated: | Apr 15 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Lorenzo Hernandez Garcia-Hierro" <[email protected]>. |
| Vulnerable: |
osCommerce osCommerce 2.2 cvs |
| Not Vulnerable: | |
Discussion
OSCommerce Authentication Bypass Vulnerability
osCommerce has been reported prone to authentication bypass vulnerability.
It has been reported that osCommerce uses HTTP header information as a part of its authentication mechanism. Reportedly an attacker may spoof parts of the HTTP header and, in doing so, subvert osCommerce authentication systems set in place.
This attack may be used in conjunction with other attacks to disclose, what may be sensitive information, to the attacker.
It should be noted that although osCommerce version 2.2cvs was reported vulnerable, previous versions may also be affected.
osCommerce has been reported prone to authentication bypass vulnerability.
It has been reported that osCommerce uses HTTP header information as a part of its authentication mechanism. Reportedly an attacker may spoof parts of the HTTP header and, in doing so, subvert osCommerce authentication systems set in place.
This attack may be used in conjunction with other attacks to disclose, what may be sensitive information, to the attacker.
It should be noted that although osCommerce version 2.2cvs was reported vulnerable, previous versions may also be affected.
Exploit / POC
OSCommerce Authentication Bypass Vulnerability
The following proof of concept has been made available:
http://www.example.com/oscommerce_installation/default.php/cPath/../../../../../
The following proof of concept has been made available:
http://www.example.com/oscommerce_installation/default.php/cPath/../../../../../
Solution / Fix
OSCommerce Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.