Showing posts with label osCommerce. Show all posts
Showing posts with label osCommerce. Show all posts

Friday, 31 January 2014

[EN] osCommerce 3.0.2 - Multiple XSS

In latest version of osCommerce (3.x line) I found few XSS bugs.

As they are only exploitable when admin user is logged in,
Support of osCommerce said that this is low priority bug.

It will not be published until patch release.

By the way I must say that Support Team was very fast in reply for my message,
so big plus guys! ;)

Friday, 4 October 2013

[EN] osCommerce 2.3.3.4 Exploited

Hi ;)

Durning few projects sometimes I can find that customers are using osCommerce
at their servers.

I prepare a small (poc) tool to a little bit automate a process of password cracking
and exploiting RCE available in admin panel (again ;) ).

Like I said to next week, this won't be public, sorry.
Anyway if you think that you will need it before (to test your sites or
your customers) then feel free to let me know privately, via email as always.

Have a nice day
o/

Tuesday, 12 February 2013

osCommerce 2.3.3 shell via CSRF

Few days ago I wrote about persistent XSS attack possible in latest osCommerce (2.3.3).

Today, new strony about osCommerce:
public available exploit  for  csrf in latest version.

Enjoy ;)

Monday, 7 January 2013

[EN] osCommerce 2.3.3 Exploited

I found few bugs in latest version of popular osCommerce.

Here for now will be presented only persistent XSS bug and information disclosure.

It's good practice to remember that in case of information disclosure bugs we don't need any 'error displaying'. So it will be good idea to set it to "Off" in your php.ini file.


Update:
osCommerce 2.3.3 after XSS attack



This screen presents xss for logged in user.