osCommerce osCsid Parameter Cross-Site Scripting Vulnerability
BID:9238
Info
osCommerce osCsid Parameter Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9238 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2003 12:00AM |
| Updated: | Dec 17 2003 12:00AM |
| Credit: | The disclosure of this issue has been credtied to JeiAr <[email protected]>. |
| Vulnerable: |
osCommerce osCommerce 2.2 ms2 osCommerce osCommerce 2.2 ms1 osCommerce osCommerce 2.2 cvs |
| Not Vulnerable: |
osCommerce osCommerce 2.2 ms3 |
Discussion
osCommerce osCsid Parameter Cross-Site Scripting Vulnerability
It has been reported that osCommerce may be prone to a cross-site scripting vulnerability that may allow an attacker to construct a malicious link containing HTML or script code that may be rendered in a user's browser.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Although unconfirmed, osCommerce versions 2.2 Milestone 1 and 2.2 Milestone 2 may be vulnerable to this issue.
It has been reported that osCommerce may be prone to a cross-site scripting vulnerability that may allow an attacker to construct a malicious link containing HTML or script code that may be rendered in a user's browser.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Although unconfirmed, osCommerce versions 2.2 Milestone 1 and 2.2 Milestone 2 may be vulnerable to this issue.
Exploit / POC
osCommerce osCsid Parameter Cross-Site Scripting Vulnerability
The following proof of concept has been provided:
https://www.example.com/?osCsid="><iframe src=http://www.example.com></iframe>
The following proof of concept has been provided:
https://www.example.com/?osCsid="><iframe src=http://www.example.com></iframe>
Solution / Fix
osCommerce osCsid Parameter Cross-Site Scripting Vulnerability
Solution:
It has been reported that osCommerce 2.2 Milestone 3 is not affected by this issue. Users are advised to contact the vendor for more information about obtaining fixes.
Solution:
It has been reported that osCommerce 2.2 Milestone 3 is not affected by this issue. Users are advised to contact the vendor for more information about obtaining fixes.
References
osCommerce osCsid Parameter Cross-Site Scripting Vulnerability
References:
References:
- osCommerce Homepage (osCommerce)
- osCommerce Malformed Session ID XSS Vuln (JeiAr
)