vendor:
CS-Cart
by:
GulfTech Security Research
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: CS-Cart
Affected Version From: CS-Cart <= 1.3.5
Affected Version To: CS-Cart <= 1.3.5
Patch Exists: YES
Related CWE: N/A
CPE: a:cs-cart.com:cs-cart
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
CS-Cart <= 1.3.5 SQL Injection Vulnerability
CS-Cart Cart is a full featured online ecommerce application written in php that allows users to build, run and promote an online store. There is unfortunately a fairly serious SQL Injection issue within CS-Cart that can be used to easily take over user and administrator accounts, as well as used to retrieve arbitrary data from the database. The vulnerable code can be found in /core/user.php, where an attacker can specify a cookie like cs_cookies[customer_user_id]=1'/*; and successfully log in as the customer with the id of 1 without ever actually authenticating.
Mitigation:
Upgrade to the latest version of CS-Cart to resolve this issue.