Alabanza AlaCart Administration Authentication Bypass SQL Injection Vulnerability
BID:9136
Info
Alabanza AlaCart Administration Authentication Bypass SQL Injection Vulnerability
| Bugtraq ID: | 9136 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2003 12:00AM |
| Updated: | Dec 01 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Robert diandro <[email protected]>. |
| Vulnerable: |
Alabanza AlaCart 1.0 |
| Not Vulnerable: | |
Discussion
Alabanza AlaCart Administration Authentication Bypass SQL Injection Vulnerability
It has been reported that AlaCart Shopping Cart is prone to SQL injection attacks. The problem occurs when handling user-supplied username and password data supplied to authentication procedures.
To exploit this vulnerability, an attacker may inject the username and password with specially formatted SQL code, and effectively manipulate the logic of the statement. When the statement execution is completed, the attacker will be successfully logged in as an administrator.
It has been reported that AlaCart Shopping Cart is prone to SQL injection attacks. The problem occurs when handling user-supplied username and password data supplied to authentication procedures.
To exploit this vulnerability, an attacker may inject the username and password with specially formatted SQL code, and effectively manipulate the logic of the statement. When the statement execution is completed, the attacker will be successfully logged in as an administrator.
Exploit / POC
Alabanza AlaCart Administration Authentication Bypass SQL Injection Vulnerability
An attacker may exploit this issue by including a username of 'or' and a password of '='.
An attacker may exploit this issue by including a username of 'or' and a password of '='.
Solution / Fix
Alabanza AlaCart Administration Authentication Bypass SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Alabanza AlaCart Administration Authentication Bypass SQL Injection Vulnerability
References:
References:
- Alabanza Homepage (Alabanza)