[UNIX] LiteCommerce SQL Injection and Source Disclosure

From: SecuriTeam (support_at_securiteam.com)
Date: 04/12/05

  • Next message: SecuriTeam: "[UNIX] TowerBlog Administrative Authentication Bypassing"
    To: list@securiteam.com
    Date: 12 Apr 2005 15:22:51 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      LiteCommerce SQL Injection and Source Disclosure
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.litecommerce.com/> LiteCommerce is "a lightweight high-tech
    ecommerce solution devoted to make an Internet store launching as easy as
    surfing the web". Two types of vulnerabilities have been discovered in
    LiteCommerce, one allows execution of arbitrary SQL statements, while the
    other allows exposing the original PHP code.

    DETAILS

    Exploits:
    The following URL will cause the PHP code exposure:
    http://localhost/test/cart.php?target='PHP_SCRIPT_EXPOSURE

    The following two URLs will trigger an error message from the remote host
    as a result of it being vulnerable to an SQL injection vulnerability:
    http://localhost/test/cart.php?target=category&category_id='SQL_INJECTION
    http://localhost/test/cart.php?target=product&product_id='SQL_INJECTION
    &category_id=246

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:dcrab@hackerscenter.com>
    dcrab.
    The original article can be found at:
    <http://digitalparadox.org/advisories/lico.txt>
    http://digitalparadox.org/advisories/lico.txt

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[UNIX] TowerBlog Administrative Authentication Bypassing"

    Relevant Pages

    • [UNIX] Sympa Mailing List System Cross Site Scripting
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... cross site scripting vulnerabilities. ... The creation list option is vulnerable to cross site-scripting attacks. ...
      (Securiteam)
    • [NEWS] HP OpenView Network Node Manager Multiple CGI Buffer Overflows
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Authentication is not required to exploit these vulnerabilities. ... The specific flaws exists within the CGI applications that handle the ...
      (Securiteam)
    • [NT] FutureSoft TFTP Server 2000 Buffer Overflow and Directory Traversal
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Two vulnerabilities were identified in FutureSoft TFTP Server, ...
      (Securiteam)
    • [UNIX] Multiple Vulnerabilities in phpMyAdmin (External Transformations)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Two vulnerabilities in phpMyAdmin have been discovered, ... vulnerabilities allow command execution and disclosure of sensitive files. ...
      (Securiteam)
    • [UNIX] Multiple XSS Vulnerabilities in WordPress
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The WordPress product has been found to contain multiple cross site ... cross site scripting vulnerabilities: ...
      (Securiteam)