Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.805566
Kategorie:Web application abuses
Titel:osCMax e-commerce/shopping-cart Multiple Vulnerabilities
Zusammenfassung:The host is installed with osCMax and is; prone to multiple vulnerabilities.
Beschreibung:Summary:
The host is installed with osCMax and is
prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist as,

- Input passed via 'username' POST parameter to /admin/login.php script,
'pageTitle' GET parameter to /admin/new_attributes_include.php script, the
'sb_id', 'sb_key', 'gc_id', 'gc_key' and 'path' POST parameters to
/admin/htaccess.php script, the 'title' GET parameter to
/admin/information_form.php script, the 'search' GET parameter to
/admin/xsell.php script, the 'gross' and 'max' GET parameters to
/admin/stats_products_purchased.php script, the 'status' GET parameter to
/admin/stats_monthly_sales.php script, the 'sorted' GET parameter to
/admin/stats_customers.php script, the 'information_id' GET parameter to
/admin/information_manager.php script, the 'zID' GET parameter to
/admin/geo_zones.php script, the 'current_product_id' and 'cPath' GET parameters
to /admin/new_attributes_include.php script is not properly sanitised before
being returned to the user.

- Input passed via the 'status' GET parameter to /admin/stats_monthly_sales.php
script, the 'country' POST parameter to /admin/create_account_process.php script,
the 'username' POST parameter to /admin/login.php script is not properly sanitised
before being used in SQL query.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to inject or manipulate SQL queries in the back-end database, allowing
for the manipulation or disclosure of arbitrary data and also create a specially
crafted URL that would execute arbitrary script code in a user's browser within
the trust relationship between their browser and the server.

Affected Software/OS:
osCMax before version 2.5.1

Solution:
Upgrade to osCMax version 2.5.1 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: BugTraq ID: 52886
Common Vulnerability Exposure (CVE) ID: CVE-2012-1665
Bugtraq: 20120404 Multiple vulnerabilities in osCmax (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2012-04/0021.html
https://www.htbridge.com/advisory/HTB23081
http://www.osvdb.org/80900
http://www.osvdb.org/80901
http://www.osvdb.org/80902
Common Vulnerability Exposure (CVE) ID: CVE-2012-1664
http://www.osvdb.org/80903
http://www.osvdb.org/80904
http://www.osvdb.org/80905
http://www.osvdb.org/80906
http://www.osvdb.org/80907
http://www.osvdb.org/80908
http://www.osvdb.org/80909
http://www.osvdb.org/80910
http://www.osvdb.org/80911
http://www.osvdb.org/80912
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.