vendor:
osCommerce
by:
Ahmed Aboul-Ela
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: osCommerce
Affected Version From: v2.3.3.4
Affected Version To: Prior versions
Patch Exists: YES
Related CWE: N/A
CPE: oscommerce
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
osCommerce v2.x SQL Injection Vulnerability
An authenticated admin account is required to successfully exploit the vulnerability, but it can be combined with other attack vectors like XSS / CSRF to achieve more dangerous successful remote attack. An example of this is to steal the administrator username & password and send it to a php logger at 'http://evilsite.com/logger.php?log=[ADMIN USER:HASH]'. A hybrid attack technique (SQL Injection + XSS) can also be used.
Mitigation:
Input validation should be used to prevent SQL injection attacks. Additionally, XSS attacks should be prevented by using a web application firewall or by sanitizing user input.