Информационная безопасность
[RU] switch to English

Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  SiteXpress SQL Injection

  SiteXpress SQL Injection

  [Full-disclosure] Advisory 14/2006: Dotdeb PHP Email Header Injection Vulnerability

  ASPintranet SQL Injection

From:Aesthetico <admin_(at)_majorsecurity.de>
Date:14 ноября 2006 г.
Subject:[MajorSecurity Advisory #33]ShopSystems - SQL Injection Issue

[MajorSecurity Advisory #33]ShopSystems - SQL Injection Issue

Product: ShopSystems
Affected Version: <= 4.0
Immune Version: none
Security-Risk: moderated
Remote-Exploit: yes
Vendor-URL: http://www.shopsystems.biz
Vendor-Status: informed
Advisory-Status: published

Discovered by: David Vieira-Kurz

Original Advisory:

ShopSystems is a web shop system.

More Details
SQL injection:
Input passed directly to the "sessid" parameter in "index.php" is not properly sanitised before being used in a SQL query.
This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

none known

Edit the source code to ensure that input is properly sanitised.
You should work with the "intval()" and "mysql_real_escape_string()" or "addslashes()" php-function to ensure that sql statements
can't be delivered over the "get" variables.

$pass = htmlentities($_POST['pass']);
$test = htmlspecialchars($_GET('test'));
$id = intval($_POST['id']);

03.11.2006 discovery of the vulnerability
04.11.2006 additional tests with other versions
04.11.2006 contacted the vendor
11.11.2006 advisory is written
11.11.2006 advisory released

MajorSecurity is a German penetration testing and security research project
which consists of only one person at the present time.
I am looking for a sponsor.
You can find more Information on the MajorSecurity Project at

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород