SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Commerce)  >  CommerceSQL Vendors:  Internet Express Products
CommerceSQL Shopping Cart Discloses Files to Remote Users
SecurityTracker Alert ID:  1008291
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Nov 25 2003
Impact:  Disclosure of system information, Disclosure of user information
Exploit Included:  Yes  
Description:  A vulnerability was reported in the CommerceSQL shopping cart. A remote user can view files on the system with the privileges of the web server.

It is reported that the 'index.cgi' script does not validate user-supplied input for the 'page' variable. A remote user can submit a specially crafted HTTP request to view arbitrary files on the system that are readable by the web server process.

A demonstration exploit is provided:

index.cgi?page=../../../../../../../../etc/passwd

Impact:  A remote user can view files on the system with the privileges of the web server daemon.
Solution:  No solution was available at the time of this entry.
Vendor URL:  commercesql.com/ (Links to External Site)
Cause:  Input validation error
Underlying OS:  Linux (Any), UNIX (Any)
Reported By:  Mariusz Ciesla <craig@tenbit.pl>
Message History:   None.


 Source Message Contents

Date:  23 Nov 2003 18:47:39 -0000
From:  Mariusz Ciesla <craig@tenbit.pl>
Subject:  [CommerceSQL] Remote File Read Vulnerability

 



CommerceSQL shopping cart (http://commercesql.com) allows remote file reading. It only needs to speci
ally prepared page variable in index.cgi to allow reading remote files (like /etc/passwd) By using prepared GET page variable it allows user to read remote files Example: With index.cgi?page=../../../../../../../../etc/passwd puts out your /etc/passwd on the screen of pot
tential attacker. Vulnerable: * All CommerceSQL Shopping Cart Versions Exploits: * Not needed Patch: * Not yet available -- Mariusz "Craig" Cie&#347;la <craig@tenbit.pl> getNet network administrator / security consultant


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2003, SecurityGlobal.net LLC