|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[SA12026] Comersus Shopping Cart Cross-Site Scripting and Price Manipulation
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Thu Jul 08 2004 - 02:49:49 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
TITLE:
Comersus Shopping Cart Cross-Site Scripting and Price Manipulation
SECUNIA ADVISORY ID:
SA12026
VERIFY ADVISORY:
http://secunia.com/advisories/12026/
CRITICAL:
Moderately critical
IMPACT:
Cross Site Scripting, Manipulation of data
WHERE:
From remote
SOFTWARE:
Comersus Shopping Cart 5.x
http://secunia.com/product/3664/
Comersus Shopping Cart 4.x
http://secunia.com/product/1801/
DESCRIPTION:
Thomas Ryan has reported some vulnerabilities in Comersus Shopping
Cart, which can be exploited by malicious people to conduct
cross-site scripting attacks or manipulate orders.
1) Input passed to certain parameters in the following scripts isn't
properly sanitised before being returned to users.
* "store/comersus_customerAuthenticateForm.asp"
* "backofficeLite/comersus_backoffice_message.asp"
* "store/comersus_supportError.asp"
* "store/comersus_message.asp"
This can be exploited to execute arbitrary HTML and script code in a
user's browser session in context of a vulnerable site by tricking
the user into visiting a malicious website or follow a specially
crafted link.
2) Orders are reportedly submitted insecurely via a GET request to
the "store/comersus_gatewayPayPal.asp" script. This can be exploited
by malicious users to manipulate input in various parameters
including pricing.
The vulnerabilities have been reported in version 5.09. Other
versions may also be affected.
SOLUTION:
Update to version 5.098.
http://www.comersus.com/
PROVIDED AND/OR DISCOVERED BY:
Thomas Ryan, Provide Security.
ORIGINAL ADVISORY:
http://www.providesecurity.com/research/advisories/07062004-01.asp
http://www.providesecurity.com/research/advisories/07062004-02.asp
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]