Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [cosmoshop <= 8.10.78] be the shopadmin in one step |
|---|---|
| Date: | 29 Aug 2005 05:24:50 -0000 |
author : l0om innate| @t | gmx.de
WWW.EXCLUDED.ORG
product: cosmoshop
version: <= 8.10.78
problem: 1. sql injection
2. cleartext passwords
3. view any file
maunuf.: www.cosmoshop.de
what is cosmoshop
*****************
cosmoshop is a comercial shop system written as a CGI.
where is the problem
********************
1. sql injection
----------------
the administration login panel suffers from a bad written login function caused
by unfiltered parameters which are put into a sql query. everyone can log in as
admin and can change the pages content. the best/worst of it is: you can
download a mysql dump of the whole shop with the "backup" feature...
other features are:
Article, Columns, Statistics, Supplier, Attitudes, Texts, Design,
Orderprocedure, Mailtexts, Auxiliary-sides, Interfaces, Newletter, Coupons
2. passwords saved in cleartext
-------------------------------
the passwords are stored in cleartext within the database!
3. view any file
----------------
in the "bestmail_edit.cgi" you can view any file in the system which can be
viewed with the permissions of the werbserver if you use the "file" parameter
like "..&file=../../[..]/etc/passwd".
you have to be logged in as admin to use this "feature". to log in as admin see
(1). ;)
solution?
*********
- use htaccess login for the administration interface.
- update to a fixed version.
where to get fixed version?
***************************
somewhere over the rainbow...
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Multiple CMS/Forum Vulnablilties, pacifico\", 0] //--></script>a |
|---|---|
| Next by Date: | Land Down Under 801 And Prior Multiple SQL Injection Vulnerabilities, h4cky0u . org |
| Previous by Thread: | Multiple CMS/Forum Vulnablilties, pacifico\", 0] //--></script>a |
| Next by Thread: | Land Down Under 801 And Prior Multiple SQL Injection Vulnerabilities, h4cky0u . org |
| Indexes: | [Date] [Thread] [Top] [All Lists] |