vendor:
XT-Commerce
by:
indoushka
7,5
CVSS
HIGH
Backup
N/A
CWE
Product Name: XT-Commerce
Affected Version From: v1 Beta 1
Affected Version To: v1 Beta 1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
XT-Commerce v1 Beta 1 => by Pass / Creat and Download Backup Vulnerability
A vulnerability exists in XT-Commerce v1 Beta 1 which allows an attacker to bypass authentication and create and download a backup. The attacker can access the backup.php/login.php page with the action parameter set to backupnow to create a backup. The attacker can then access the backup.php/login.php page with the action parameter set to download and the file parameter set to the name of the backup to download it.
Mitigation:
Upgrade to the latest version of XT-Commerce v1 Beta 1.