vendor:
VamCart
by:
Vulnerability Laboratory Research Team
5,5
CVSS
MEDIUM
Persistent Input Validation Vulnerabilities
79
CWE
Product Name: VamCart
Affected Version From: VamCart v0.9
Affected Version To: VamCart v0.9
Patch Exists: NO
Related CWE: N/A
CPE: a:vamcart:vamcart:0.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
VamCart v0.9 CMS – Multiple Web Vulnerabilities
Multiple persistent input validation vulnerabilities are detected in the VamCart v0.9 Content Management System. The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent). The persistent vulnerabilities are located in the manage accounts, manage coupons, view orders or order comments module(s) with the bound vulnerable parameters comment text, coupon code, title & name. Exploitation requires low user inter action & privileged application user account. Successful exploitation of the vulnerability can lead to session hijacking (admin) or stable (persistent) context manipulation.
Mitigation:
Edit the source code to secure the vulnerable parameters and update the application