[NT] StoreFront Vulnerable to SQL Injection

From: SecuriTeam (support_at_securiteam.com)
Date: 07/15/03

  • Next message: SecuriTeam: "[UNIX] Format String Vulnreability Found in ImageMagick"
    To: list@securiteam.com
    Date: 15 Jul 2003 15:43:47 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    Beyond Security in Canada

    Toronto-based Sunrays Technologies is now Beyond Security's representative in Canada.
    We welcome ISPs, system integrators and IT systems resellers
    to promote the most advanced vulnerability assessment solutions today.

    Contact us at 416-482-0038 or at canadasales@beyondsecurity.com

    - - - - - - - - -

      StoreFront Vulnerable to SQL Injection
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.storefront.net/products/6.0/landing.asp> StoreFront "offers
    merchants and developers a feature rich, fully customizable e-commerce
    solution at a fraction of the cost to deploy and maintain". An SQL
    injection vulnerability in the product allows remote attackers to bypass
    the login screen, and gain access to sensitive information located in the
    database, further, depending on the database server backend, command
    execution will be possible.

    DETAILS

    Vulnerable systems:
     * StoreFront version 6.0 and prior

    There is a SQL injection vulnerability in /login.asp of StoreFront system.
    This allows bypassing of the mechanism, and the insertion of malicious SQL
    statements.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:G00db0y@zone-h.org> G00db0y.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[UNIX] Format String Vulnreability Found in ImageMagick"