Web Merchant Services Storefront Shopping Cart login.asp SQL Injection Vulnerability
BID:9301
Info
Web Merchant Services Storefront Shopping Cart login.asp SQL Injection Vulnerability
| Bugtraq ID: | 9301 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 26 2003 12:00AM |
| Updated: | Dec 26 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Chris McCoy <[email protected]>. |
| Vulnerable: |
Web Merchant Services Storefront shopping cart 5.0 |
| Not Vulnerable: | |
Discussion
Web Merchant Services Storefront Shopping Cart login.asp SQL Injection Vulnerability
It has been reported that Storefront shopping cart may be vulnerable to a SQL injection vulnerability that may allow a remote user to inject malicious SQL syntax into database queries. The problem is reported to exist due to insufficient sanitization of user-supplied data in the 'login.asp' script.
Specific vulnerable versions were not identified in the report, therefore it is being assumed that the current version Storefront shopping cart 5.0 is vulnerable to this issue.
It has been reported that Storefront shopping cart may be vulnerable to a SQL injection vulnerability that may allow a remote user to inject malicious SQL syntax into database queries. The problem is reported to exist due to insufficient sanitization of user-supplied data in the 'login.asp' script.
Specific vulnerable versions were not identified in the report, therefore it is being assumed that the current version Storefront shopping cart 5.0 is vulnerable to this issue.
Exploit / POC
Solution / Fix
Web Merchant Services Storefront Shopping Cart login.asp SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Web Merchant Services Storefront Shopping Cart login.asp SQL Injection Vulnerability
References:
References:
- Storefront shopping cart (Web Merchant Services)