Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: CyberStrong Shopping Cart - Advisory & Exploit Code

CyberStrong Shopping Cart - Advisory & Exploit Code

From: <aresu_at_bosen.net>
Date: Tue, 1 Jul 2003 11:03:35 +0700

Advisory Name: Cyberstrong eShop SQL Injection Vulnerability
Release Date: 05/07/2003
Application: CyberStrong eShop v4.2
Platform: Win32/MSSQL
Severity: High
BUG Type: SQL Injection
Discover by: AresU <aresu_at_bosen.net>
Author: Bosen <mobile_at_bosen.net>
Vendor Status: See below.
Vendor URL: http://www.cyberstrong.com/eshop
Reference: http://bosen.net/releases/

Overview:
For the commersial break pls visit
http://www.cyberstrong.com/eshop/features.asp
I know there's lotsa features there.

Details:
CyberStrong provide trial/demo software, in encrypted thought.
But the encryption not as big as its sounds like.

Well, the bugs lies on the application libraries.
And got fired via 10expand.asp, 10browse.asp, and 20review.asp.

With manipulated SQL injection, an attacker would be able to gain some
information including admin's user and admin's password.
Which is can be used thorugh web based admin interface on
/admin/mlogin.asp.

Exploits/POC:
http://[target]/eshop/10Expand.asp?ProductCode='
http://[target]/eshop/20Review.asp?ProductCode='

Vendor Response:
Contacted. No response.

Recommendation:
No recommendation for this.
For workaround, just protect /admin dir with .htpasswd.
(but its not very effective, an attacker still can do query, but at least it
would be slowing their jobs)

1ndonesian Security Team (1st) Advisory:
http://bosen.net/releases/

About 1ndonesian Security Team:
1ndonesian Security Team, research and develop intelligent, advanced
application security assessment. Based in Indonesia, 1ndonesian Security
Team offers best of breed security consulting services, specialising in
application, host and network security assessments.

1st provides security information and patches for use by the entire 1st
community.

This information is provided freely to all interested parties and may be
redistributed provided that it is not altered in any way, 1st is
appropriately
credited and the document retains.

Greetz to:
Bosen, TioEuy,Ipunk, Heltz, Gembul,TomIngShUu, sakitjiwa, muthafuka,
alphacentury,
All 1ndonesian Security Team - #hackers_at_austnet.org/centrin.net.id

AresU <aresu_at_bosen.net>
======================
Original document can be fount at http://www.bosen.net/releases/?id=23
Received on Jul 01 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos