SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Commerce)  >   CommerceSQL Vendors:   Internet Express Products
CommerceSQL Shopping Cart Discloses Files to Remote Users
SecurityTracker Alert ID:  1008291
SecurityTracker URL:  http://securitytracker.com/id/1008291
CVE Reference:   GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Nov 25 2003
Impact:   Disclosure of system information, Disclosure of user information
Exploit Included:  Yes  

Description:   A vulnerability was reported in the CommerceSQL shopping cart. A remote user can view files on the system with the privileges of the web server.

It is reported that the 'index.cgi' script does not validate user-supplied input for the 'page' variable. A remote user can submit a specially crafted HTTP request to view arbitrary files on the system that are readable by the web server process.

A demonstration exploit is provided:

index.cgi?page=../../../../../../../../etc/passwd

Impact:   A remote user can view files on the system with the privileges of the web server daemon.
Solution:   No solution was available at the time of this entry.
Vendor URL:  commercesql.com/ (Links to External Site)
Cause:   Input validation error
Underlying OS:   Linux (Any), UNIX (Any)

Message History:   None.


 Source Message Contents

Date:  23 Nov 2003 18:47:39 -0000
Subject:  [CommerceSQL] Remote File Read Vulnerability




CommerceSQL shopping cart (http://commercesql.com) allows remote file reading. It only needs to specially prepared page variable in
 index.cgi to allow reading remote files (like /etc/passwd)

By using prepared GET page variable it allows user to read remote files

Example:
With index.cgi?page=../../../../../../../../etc/passwd puts out your /etc/passwd on the screen of pottential attacker.

Vulnerable:
* All CommerceSQL Shopping Cart Versions

Exploits:
* Not needed

Patch:
* Not yet available

-- 
Mariusz "Craig" Cie&#347;la <craig@tenbit.pl>
getNet network administrator / security consultant

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2012, SecurityGlobal.net LLC