vendor:
FreeWebshop
by:
SecurityFocus
7.5
CVSS
HIGH
Spoofing, Session Handling, Brute-Force, Security-Bypass, SQL-Injection, Directory-Traversal
20, 287, 352, 89, 564, 22
CWE
Product Name: FreeWebshop
Affected Version From: 2.2.9 R2
Affected Version To: 2.2.9 R2
Patch Exists: YES
Related CWE: N/A
CPE: a:freewebshop:freewebshop:2.2.9_r2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Multiple Remote Vulnerabilities in FreeWebshop
FreeWebshop is prone to multiple remote vulnerabilities, including spoofing HTTP headers, session handling, brute-forcing passwords, security-bypass, SQL-injection, and directory-traversal. Exploiting these issues could allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities, gain unauthorized access to the affected application, and obtain sensitive information. FreeWebshop.org 2.2.9 R2 is vulnerable; other versions may also be affected.
Mitigation:
Developers should ensure that all user-supplied input is properly validated and sanitized. Additionally, developers should ensure that all authentication credentials are stored securely and that all passwords are hashed with a strong cryptographic algorithm.