[HSC Security Group] SQL Injection in Product Cart 2.6

zinho_at_hackerscenter.com
Date: 07/30/05

  • Next message: fjlj_at_wvi.com: "RO CP root exploit"
    Date: 30 Jul 2005 11:54:10 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) Hackers Center Security Group (http://www.hackerscenter.com/)
    Zinho's Security Advisory

    Desc: SQL Injection in Product Cart 2.6
    Risk: Medium to High

    An SQL injection affects Product Cart 2.6. Database Manipulation is possible.

    viewPrd.asp?idcategory='

    Vendor: http://www.earlyimpact.com/
    "Our ecommerce software is used all over the world to build and manage professional Internet stores. As one of the most comprehensive ecommerce systems available today, ProductCart combines a long list of features with intuitive management tools that make it easy for anyone to build and manage their online storefront."

    We are looking for security researchers into web application security field to join our crew. If you're interested get in contact with Zinho at
    zinho@hackerscenter.com


  • Next message: fjlj_at_wvi.com: "RO CP root exploit"

    Relevant Pages

    • [Full-Disclosure] Serious Possible SQL Injection in munchahouse.com Ecommerce site
      ... Possible SQL Injection in munchahouse.com ... 2003-2004 by YSGNet* 01 Security ... Some vulnerabilities have been discovered in munchahouse ... Successful exploitation may disclose sensitive information, ...
      (Full-Disclosure)
    • [Full-Disclosure] Serious SQL Injection in munchahouse.com : a shopping site.,
      ... Serious SQL Injection in munchahouse.com ... 2003-2004 by YSGNet* 01 Security ... Some vulnerabilities have been discovered in munchahouse ... Successful exploitation may disclose sensitive information, ...
      (Full-Disclosure)
    • [Full-disclosure] [PT-2009-13] TinX CMS SQL Injection Vulnerability
      ... TinX CMS SQL Injection vulnerability ... Positive Technologies Research Team has discovered a SQL Injection ... Research Team) using professional network security scanner MaxPatrol. ...
      (Full-Disclosure)
    • RE: Checkpoint SmartDefense
      ... Another option that can be used instead of the default SQL injection ... protection is the "worm catcher" - you can write pretty good regular ... As my expertise is web applications security, I can comment only on the ... attacks such as SQL injection or XSS, ...
      (Focus-IDS)
    • RE: SQL Injection Legalities
      ... but my interpretation of this law is that the "crime" ... > enter search terms at your discretion. ... > a security mechanism in this case. ... > system as a result of the SQL injection. ...
      (Pen-Test)