vendor:
123tkShop
by:
Michael Brooks
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: 123tkShop
Affected Version From: 2000.9.1
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
123tkShop SQL Injection Vulnerability
An attacker can gain Administrative rights with this authentication bypass exploit using a payload constructed with base64 encoding. The vulnerable code is in the ./123tkShop/shop/mainfile.php file in the is_admin function starting on line 156. The attack works regardless of the magic_quotes_gpc and register_globals settings. The exploit can be executed through the URL http://127.0.0.1/123tkShop/shop/admin.php?admin=J3VuaW9uIHNlbGVjdCAncGFzc3dvcmQnLyogOnBhc3N3b3Jk
Mitigation:
It is advised to use another shopping cart such as OsCommerce.