OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA12026] Comersus Shopping Cart Cross-Site Scripting and Price Manipulation

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Thu Jul 08 2004 - 02:49:49 CDT


TITLE:
Comersus Shopping Cart Cross-Site Scripting and Price Manipulation

SECUNIA ADVISORY ID:
SA12026

VERIFY ADVISORY:
http://secunia.com/advisories/12026/

CRITICAL:
Moderately critical

IMPACT:
Cross Site Scripting, Manipulation of data

WHERE:
From remote

SOFTWARE:
Comersus Shopping Cart 5.x
http://secunia.com/product/3664/
Comersus Shopping Cart 4.x
http://secunia.com/product/1801/

DESCRIPTION:
Thomas Ryan has reported some vulnerabilities in Comersus Shopping
Cart, which can be exploited by malicious people to conduct
cross-site scripting attacks or manipulate orders.

1) Input passed to certain parameters in the following scripts isn't
properly sanitised before being returned to users.

* "store/comersus_customerAuthenticateForm.asp"
* "backofficeLite/comersus_backoffice_message.asp"
* "store/comersus_supportError.asp"
* "store/comersus_message.asp"

This can be exploited to execute arbitrary HTML and script code in a
user's browser session in context of a vulnerable site by tricking
the user into visiting a malicious website or follow a specially
crafted link.

2) Orders are reportedly submitted insecurely via a GET request to
the "store/comersus_gatewayPayPal.asp" script. This can be exploited
by malicious users to manipulate input in various parameters
including pricing.

The vulnerabilities have been reported in version 5.09. Other
versions may also be affected.

SOLUTION:
Update to version 5.098.
http://www.comersus.com/

PROVIDED AND/OR DISCOVERED BY:
Thomas Ryan, Provide Security.

ORIGINAL ADVISORY:
http://www.providesecurity.com/research/advisories/07062004-01.asp
http://www.providesecurity.com/research/advisories/07062004-02.asp

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------