ProductCart Login.ASP SQL Injection Vulnerability
BID:8105
Info
ProductCart Login.ASP SQL Injection Vulnerability
| Bugtraq ID: | 8105 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2003 12:00AM |
| Updated: | Jul 04 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Bosen <[email protected]>. |
| Vulnerable: |
Early Impact ProductCart 2.0 br000 Early Impact ProductCart 2.0 Early Impact ProductCart 1.6003 Early Impact ProductCart 1.6002 Early Impact ProductCart 1.5004 Early Impact ProductCart 1.5003 r Early Impact ProductCart 1.5003 Early Impact ProductCart 1.5002 Early Impact ProductCart 1.6 br003 Early Impact ProductCart 1.6 br001 Early Impact ProductCart 1.6 br Early Impact ProductCart 1.6 b003 Early Impact ProductCart 1.6 b002 Early Impact ProductCart 1.6 b001 Early Impact ProductCart 1.6 b Early Impact ProductCart 1.5 |
| Not Vulnerable: | |
Discussion
ProductCart Login.ASP SQL Injection Vulnerability
ProductCart has been reported prone to an SQL injection vulnerability that may be exploited to bypass the ProductCart authentication system and access the ProductCart administration panel; other attacks may also be possible.
ProductCart has been reported prone to an SQL injection vulnerability that may be exploited to bypass the ProductCart authentication system and access the ProductCart administration panel; other attacks may also be possible.
Exploit / POC
ProductCart Login.ASP SQL Injection Vulnerability
The following proof of concept has been supplied:
http://www.example.com/produccart/pdacmin/login.asp?idadmin='' or 1=1--
The following proof of concept has been supplied:
http://www.example.com/produccart/pdacmin/login.asp?idadmin='' or 1=1--
Solution / Fix
ProductCart Login.ASP SQL Injection Vulnerability
Solution:
The vendor has advised users of ProductCart v2 to contact [email protected] to receive an updated version of "pcadmin/login.asp".
Users of ProductCart 1.5 and earlier are advised to contact [email protected] to obtain the latest version of ProductCart.
Solution:
The vendor has advised users of ProductCart v2 to contact [email protected] to receive an updated version of "pcadmin/login.asp".
Users of ProductCart 1.5 and earlier are advised to contact [email protected] to obtain the latest version of ProductCart.