Stockman Shopping Cart Arbitrary Command Execution Vulnerability
BID:7485
Info
Stockman Shopping Cart Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 7485 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2003 12:00AM |
| Updated: | May 01 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Aleksey Sintsov <[email protected]>. |
| Vulnerable: |
Dr. Jay Stockman Stockman Shopping Cart 7.8 |
| Not Vulnerable: | |
Discussion
Stockman Shopping Cart Arbitrary Command Execution Vulnerability
Stockman Shopping Cart has been reported prone to a remote command execution vulnerability. This issue presents itself in the 'shop.plx' script.
The problem results from a lack of sufficient sanitization performed on user supplied URI parameters to the 'shop.plx' script. An attacker may exploit this vulnerability to execute arbitrary commands in the context of the web server hosting the vulnerable script.
It should be noted that although this vulnerability has been reported to affect Stockman Shopping Cart Version 7.8 other versions might also be affected.
The precise technical details of this vulnerability are currently unknown. This BID will be updated, as further information is available.
Stockman Shopping Cart has been reported prone to a remote command execution vulnerability. This issue presents itself in the 'shop.plx' script.
The problem results from a lack of sufficient sanitization performed on user supplied URI parameters to the 'shop.plx' script. An attacker may exploit this vulnerability to execute arbitrary commands in the context of the web server hosting the vulnerable script.
It should be noted that although this vulnerability has been reported to affect Stockman Shopping Cart Version 7.8 other versions might also be affected.
The precise technical details of this vulnerability are currently unknown. This BID will be updated, as further information is available.
Exploit / POC
Stockman Shopping Cart Arbitrary Command Execution Vulnerability
The following proof of concept has been supplied:
http://www.example.com/cgi-bin/shop.plx/SID=313130332/page=;cat%20..;ls|
The following exploit was provided:
The following proof of concept has been supplied:
http://www.example.com/cgi-bin/shop.plx/SID=313130332/page=;cat%20..;ls|
The following exploit was provided:
Solution / Fix
Stockman Shopping Cart Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Stockman Shopping Cart Arbitrary Command Execution Vulnerability
References:
References: