vendor:
Opencart
by:
Todor Donev
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Opencart
Affected Version From: 3.0.3.2
Affected Version To: 3.0.3.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2019
Opencart <= 3.0.3.2 'extension/feed/google_base' Remote Denial of Service PoC exploit
This PoC exploit is for Opencart versions <= 3.0.3.2. It is a remote denial of service exploit that targets the 'extension/feed/google_base' route. It has been tested on stores with more than 1000 products added. The exploit is used by running the cartkiller.sh script with the store URL, the number of threads, and the sleep time as parameters.
Mitigation:
Upgrade to the latest version of Opencart, which is 3.0.3.6.