In latest version of osCommerce (3.x line) I found few XSS bugs.
As they are only exploitable when admin user is logged in,
Support of osCommerce said that this is low priority bug.
It will not be published until patch release.
By the way I must say that Support Team was very fast in reply for my message,
so big plus guys! ;)
Showing posts with label osCommerce. Show all posts
Showing posts with label osCommerce. Show all posts
Friday, 31 January 2014
Friday, 4 October 2013
[EN] osCommerce 2.3.3.4 Exploited
Hi ;)
Durning few projects sometimes I can find that customers are using osCommerce
at their servers.
I prepare a small (poc) tool to a little bit automate a process of password cracking
and exploiting RCE available in admin panel (again ;) ).
Like I said to next week, this won't be public, sorry.
Anyway if you think that you will need it before (to test your sites or
your customers) then feel free to let me know privately, via email as always.
Have a nice day
o/
Durning few projects sometimes I can find that customers are using osCommerce
at their servers.
I prepare a small (poc) tool to a little bit automate a process of password cracking
and exploiting RCE available in admin panel (again ;) ).
Like I said to next week, this won't be public, sorry.
Anyway if you think that you will need it before (to test your sites or
your customers) then feel free to let me know privately, via email as always.
Have a nice day
o/
Labels:
0day,
code review,
exploit,
linux,
osCommerce,
research,
tools,
vulnerability
Tuesday, 12 February 2013
osCommerce 2.3.3 shell via CSRF
Few days ago I wrote about persistent XSS attack possible in latest osCommerce (2.3.3).
Today, new strony about osCommerce:
public available exploit for csrf in latest version.
Enjoy ;)
Today, new strony about osCommerce:
public available exploit for csrf in latest version.
Enjoy ;)
Monday, 7 January 2013
[EN] osCommerce 2.3.3 Exploited
I found few bugs in latest version of popular osCommerce.
Here for now will be presented only persistent XSS bug and information disclosure.
It's good practice to remember that in case of information disclosure bugs we don't need any 'error displaying'. So it will be good idea to set it to "Off" in your php.ini file.
Update:
This screen presents xss for logged in user.
Here for now will be presented only persistent XSS bug and information disclosure.
It's good practice to remember that in case of information disclosure bugs we don't need any 'error displaying'. So it will be good idea to set it to "Off" in your php.ini file.
Update:
![]() | |||
| osCommerce 2.3.3 after XSS attack |
Labels:
0day,
code review,
exploit,
osCommerce,
rce,
vulnerability
Subscribe to:
Posts (Atom)
