Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  VMSA-2008-0015 Updated ESXi and ESX 3.5 packages address critical security issue in openwsman

  Advanced Electron Forum <= 1.0.6 Remote Code Execution

  Annuaire Téléphoniqu
e v1.0 Sensetive Files (MDP)

  PHP pro bid v 6.04 SQL injection

From:John Cobb <johnc_(at)_nobytes.com>
Date:20.09.2008
Subject:[NOBYTES.COM: #12] osCommerce 2.2rc2a - Information Disclosure

Application:            osCommerce 2.2rc2a
Authors Site:           http://www.oscommerce.com/

+--------------------------------------------------------------+

Information Disclosure:

Manipulation of the 'DOB' Variable on create_account.php can cause
information disclosure:


In this example the POST variable 'DOB' has been set to: FOOBAR

POST /oscommerce/create_account.php

action=process&gender=m&firstname=john&lastname=smith&dob=FOOBAR&
email_addre
ss=email@address.
com&company=foobar&street_address=foobar&suburb=foobar&post
code=foobar&city=foobar&state=foobar&country=1&telephone1=1234567
89&fax=1234
56789&newsletter=on&password=foobar&confirmation=foobar

Result:

Warning: checkdate() expects parameter 3 to be long, string given in
/var/www/oscommerce/create_account.php on line 80


+-[Notes:]-----------------------------------------------------+

Vulnerabilities found on: 05/09/2008
Author(s) Informed on: 06/09/2008
Author(s) Response: None Yet
Author(s) Fix: None Yet


JohnC@NoBytes.com

http://www.NoBytes.com

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru