osCommerce SQL Injection Vulnerability
BID:9211
Info
osCommerce SQL Injection Vulnerability
| Bugtraq ID: | 9211 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2003 12:00AM |
| Updated: | Dec 13 2003 12:00AM |
| Credit: | Discovered by JeiAr <[email protected]>. |
| Vulnerable: |
osCommerce osCommerce 2.2 ms1 |
| Not Vulnerable: |
osCommerce osCommerce 2.2 ms2 |
Discussion
osCommerce SQL Injection Vulnerability
It has been reported that one of the scripts included with osCommerce fails to validate user-supplied input, rendering it vulnerable to a SQL injection attack. The script in question is used to verify account details during the new user registration process and has the filename "create_account_process.php". It may be possible for attackers to manipulate the query to corrupt data in the database or, possibly, gain access on the underlying host (through, for example, stored procedures or vulnerabilities in the database server).
It has been reported that one of the scripts included with osCommerce fails to validate user-supplied input, rendering it vulnerable to a SQL injection attack. The script in question is used to verify account details during the new user registration process and has the filename "create_account_process.php". It may be possible for attackers to manipulate the query to corrupt data in the database or, possibly, gain access on the underlying host (through, for example, stored procedures or vulnerabilities in the database server).
Exploit / POC
osCommerce SQL Injection Vulnerability
The following proof of concept exploit has been supplied:
The following proof of concept exploit has been supplied:
Solution / Fix
osCommerce SQL Injection Vulnerability
Solution:
This vulnerability is reportedly fixed in version 2.2-MS2. The vendor has also released an update package for osCommerce 2.2 Milestone 1.
osCommerce osCommerce 2.2 ms1
Solution:
This vulnerability is reportedly fixed in version 2.2-MS2. The vendor has also released an update package for osCommerce 2.2 Milestone 1.
osCommerce osCommerce 2.2 ms1
-
osCommerce oscommerce-2.2ms2.zip
http://easynews.dl.sourceforge.net/sourceforge/tep/oscommerce-2.2ms2.z ip -
osCommerce oscommerce-22ms1-20031216.tar.gz
http://www.oscommerce.com/ext/oscommerce-22ms1-20031216.tar.gz
References
osCommerce SQL Injection Vulnerability
References:
References:
- osCommerce 2.2 Milestone 1 SQL Injection Vulnerability (Fix) (osCommerce)
- osCommerce Homepage (osCommerce)
- osCommerce 2.2-MS1 SQL Injection Vulnerability (JeiAr
) - Re:Re: SQL Injection Vuln In osCommerce 2.2-MS1 (JeiAr
)