vendor:
Zen Cart
by:
Dr. Alberto Fontanella
8.8
CVSS
HIGH
Full Path Disclosure, Reflected Cross-Site Scripting (XSS), Stored Cross-Site Scripting (XSS)
79, 79, 79
CWE
Product Name: Zen Cart
Affected Version From: 1.3.9f
Affected Version To: 1.3.9h
Patch Exists: YES
Related CWE: N/A
CPE: a:zen-cart:zen_cart
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: BackTrack 4
2011
Multiple Vulnerabilities in Zen Cart
An error occurs when an attacker points a single page. This leads to discover the full path of web server and vhost directory. The 'Quantity' field of Store Product don't sanitizes user input before to show output back to user. This leads an attacker to inject and execute arbitrary javascript and/or html code. You have to be logged as Admin. The 'Zones Name & Code' fields of Locations/Taxes don't sanitizes user input before to store it into database and to show output back to user. This leads an attacker to inject and execute arbitrary javascript and/or html code.
Mitigation:
Sanitize user input before to show output back to user and store it into database.