PHPShop 2.1 Vulnerabilities

2011.09.20
Credit: MustLive
Risk: Low
Local: No
Remote: Yes
CWE: CWE-79


CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

Hello Bugtraq! I want to warn you about Insufficient Anti-automation, Cross-Site Scripting, Denial of Service and Full path disclosure vulnerabilities in PHPShop. This is engine for online shops. ------------------------- Affected products: ------------------------- Vulnerable are PHPShop 2.1 EE and previous versions (and potentially next versions). ---------- Details: ---------- Insufficient Anti-automation (WASC-21): http://site/users/register.html At this page the vulnerable captcha is using. http://websecurity.com.ua/uploads/2010/PHPShop%20CAPTCHA%20bypass.html http://site/users/sendpassword.html At this page there is no protection against automated requests (captcha). XSS (with captcha bypass) (WASC-08): http://websecurity.com.ua/uploads/2010/PHPShop%20XSS.html DoS (WASC-10): http://site/search/?words=.&p=all&cat=0 Full path disclosure (WASC-13): http://site/page/? ------------ Timeline: ------------ 2010.09.08 - announced at my site. 2010.09.11 - informed developers. 2010.11.06 - disclosed at my site. I mentioned about these vulnerabilities at my site (http://websecurity.com.ua/4512/). Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua

References:

http://xforce.iss.net/xforce/xfdb/63157
http://www.securityfocus.com/bid/44763
http://www.securityfocus.com/archive/1/archive/1/514672/100/0/threaded
http://websecurity.com.ua/4512/
http://secunia.com/advisories/42132
http://osvdb.org/69101


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top