Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl)

  Vulnerabilities in SPIP

  XMB Forum 1.9.5-Final XSS

  interaktiv.shop v.5 XSS vuln.

  MyBB 1.10 'newthread.
php' < CrossSiteScripting >

From:r0t <krustevs_(at)_googlemail.com>
Date:10 апреля 2006 г.
Subject:Shopweezle 2.0 multiple vuln.

Shopweezle 2.0 multiple vuln.

###############################################
Vuln. discovered by : r0t
Date: 9 april 2006
vendor:http://shopweezle.de/
affected versions:
ShopWeezle PERSONAL
ShopWeezle PROFESSIONAL
ShopWeezle PROFESSIONAL+
orginal advisory:
http://pridels.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html
###############################################


Vuln. description:


1. SQL injection vuln.

Shopweezle contains a flaws that allows a remote sql injection
attacks.Inputpassed to the "itemID","brandID","album" isn't properly
sanitised before
being used in a SQL query. This can be exploited to manipulate SQL queries
by injecting arbitrary SQL code.

examples:

/login.php?caller=xlink&url=detail.php&itemID=1[SQL]
/index.php?x=0&itemgr=1[SQL]
/index.php?caller=xlink&url=brand.php&brandID=1[SQL]
/memo.php?itemID=1[SQL]
/index.php?x=0&caller=xlink&url=gallery.php&album=1[SQL]

2. Full Path Disclosure

An attacker can get full install path by testing SQL attack vuln.

3. Possible Local File Include vuln.

Input passed to the "url" parameter in "index.php" isn't properly verified
before being used to include files. This can be exploited to include
arbitrary files from local resources.


###############################################
Solution:
Edit the source code to ensure that input is properly sanitised.
###############################################
More information @ unsecured-systems.com/forum/

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server