what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

demostore.txt

demostore.txt
Posted Jul 24, 2006
Authored by sledge

The Demo Store version of AFCommerce Shopping Cart is susceptible to SQL injection and cross site scripting flaws.

tags | advisory, xss, sql injection
SHA-256 | af49e1fb5a31ada2438785fe63a8aee4c5ffc469e25e30ba194fe642e1d3ac99

demostore.txt

Change Mirror Download
The 'Demo Store' version of the AFCommerce Shopping Cart (www.afcommerce.com) is vulnerable to both SQL Injection and Cross Site Scripting (XSS).

SQL Injection can be tested by inserting the classic 'or 1=1-- into the search field. The result is that the first record is returned. We can also perform a UNION to return all the records.

The XSS vulnerability can be tested by registering as a new user and selecting to add a new review to a product. In the 'new review' text box we can insert some text such as:

<b>some text</b><script>alert("xxx")</script>

With this text inserted we can view the product and select 'reviews'. Upon doing this our Alert box is executed with 'xxx' then the page is displayed with the 'some text' being displayed as bold.

This are only simple example to test for these vulnerabilites. An attacker could take full advantage of these two vulnerabilities to attack the database, include malicious code or deface the site.
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close