Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  glFusion <= 1.1.2 COM_applyFilter()
/cookies remote blind sql injection exploit

  Q2 Solutions ConnX - SQL Injection Vulnerability

  [OPENX-SA-2009-002] OpenX 2.4.11, 2.6.5, 2.8.0 fix multiple vulnerabilities

  OpenX 2.6.4 multiple vulnerabilities

From:laurent.desaulniers_(at)_gmail.com <laurent.desaulniers_(at)_gmail.com>
Date:03.04.2009
Subject:OSCommerce Session Fixation Vulnerability

There is a flaw in the way OSCommerce handles sessions.

When a client visits a OSCommerce web page, the server sends a cookie. That cookie will be the session cookie for every
further requests. Thus, once logged in, the cookie will be used to authenticate the user.

When logging in (without cookies), the URL will look something like http://myserver/myapp/index.php?oscid=sometext

An attacker can send a link crafted like that http://myserver/myapp/index.php?oscid=arbitrarysession. If the admin/user
follows the link and logs in, his cookie will still be arbitrarysession. Thus, the attacker can hijack the session because
he set the cookie.

P.S. Thanks to the whole TeaM Random (www.etsmtl.ca) for this bug.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server