Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-26-2013, 01:21 AM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Exploit v
« Previous 1 ... 6 7 8 9 10 ... 15 Next »

CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities

Home General Computer Multimedia Business Lounge

Pages (2): 1 2 Next »
Post Reply 
Tweet
Threaded Mode | Linear Mode
CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
06-14-2011, 06:46 AM
Post: #1
Shamus Offline
DC Senior
***
Posts: 137
Joined: Mar 2010
Reputation: 11
CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
# Exploit Title: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
# Date: June, 14th 2011 [GMT +7]
# Author: Shamus
# Software Link: http://www.cubecart.com/
# Version : CubeCart 2.0.7
# Tested on: windows 7, ubuntu 11.04
# CVE : -

-----------------------------------------------------------------------------------------
[AJS_ADVISORIES_09&2011] CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
-----------------------------------------------------------------------------------------

Author : Shamus
Date : June, 14th 2011 [GMT +7]
Location : Solo && Jogjakarta, Indonesia
Web : http://antijasakom.net/forum
Critical Lvl : Medium
Impact : Exposure of sensitive information
Where : From Remote
---------------------------------------------------------------------------



Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~
Application : CubeCart
Version : CubeCart 2.0.7
Vendor : Devellion Limited of 5 Bridge Street,Bishops Stortford, HERTS. CM23 2JU (Company Registration Number 5323904)
Download : http://www.cubecart.com/site/downloads/
Description :
CubeCart is a fully featured ecommerce shopping cart solution used by over a million store owners around the world.
CubeCart is an "out of the box" ecommerce shopping cart software solution which has been written to run on servers that have PHP & MySQL support.
With CubeCart you can quickly setup a powerful online store which can be used to sell digital or tangible products to new and existing customers all over the world.
There are a great deal of powerful features enabling your business to trade online successfully.
It is easy to modify the look and feel of your store to match your company's branding or to site comfortably beside your existing website due to CubeCart's powerful HTML template system.
Our solutions are robust, flexible, affordable and are supported by not only a profitable and stable company but a thriving community of enthusiasts who are keen to recommend it and share their ideas and experience.
To use CubeCart you will require a compatible web hosting account. If you wish to take credit/debit card payments a merchant account will be required to work with one of the supported modules.
If you have any questions about our products or services, please be sure to contact a member of staff who will be delighted to help.

--------------------------------------------------------------------------



Vulnerability:
~~~~~~~~~~~~
A weakness has been discovered cubecart.
Where an attacker could exploit the gap that exists to obtain sensitive data within the database.
This may compromise the integrity of your database and/or expose sensitive information.
- The SQL injection vulnerability identified in the path "index.php", "view_cart.php" and "view_product.php".
- The XSS vulnerability identified in the path "search".


PoC/Exploit:
~~~~~~~~~~
SQL injection vulnerability affects:

- http://site.com/path/index.php?cat_id=%27

- http://site.com/path/view_product.php?product=%27

- http://site.com/path/view_cart.php?add=%27


XSS vulnerability affects:

- http://site.com/path/search.php

admin page:

- http://site.com/path/admin/login.php


Dork:
~~~~~
Google : inurl:"index.php?cat_id=" powered by CubeCart 2.0.7

Solution:
~~~~~
- Your script should filter metacharacters from user input.
- Edit the source code to ensure that input is properly verified.


Timeline:
~~~~~~~
- 12 - 06 - 2011 bug found.
- 12 - 06 - 2011 vendor contacted, but no response.
- 14 - 06 - 2011 Advisories release.

---------------------------------------------------------------------------



Shoutz:
~~~~~~~
oO0::::: Greetz and Thanks: :::::0Oo.
Tuhan YME
My Parents
SPYRO_KiD
K-159
lirva32
newbie_campuz

And Also My LuvLy wife :
..::.E.Z.R (The deepest Love I'v ever had..).::..

in memorial :
1. Monique
2. Dewi S.
3. W. Devi Amelia
4. S. Anna

oO0:::A hearthy handshake to: :::0Oo
~ Crack SKY Staff
~ Echo staff
~ antijasakom staff
~ jatimcrew staff
~ whitecyber staff
~ lumajangcrew staff
~ devilzc0de staff
~ unix_dbuger, boys_rvn1609, jaqk, byz9991, bius, g4pt3k, anharku, wandi, 5yn_4ck, kiddies, bom2, untouch, antcode
~ arthemist, opt1lc, m_beben, gitulaw, luvrie, poniman_coy, ThePuzci, x-ace, newbie_z, petunia, jomblo.k, hourexs_paloer, cupucyber, kucinghitam, black_samuraixxx, ucrit_penyu, wendys182, cybermuttaqin
~ k3nz0, thomas_ipt2007, blackpaper, nakuragen, candra, dewa
~ whitehat, wenkhairu, Agoes_doubleb, diki, lumajangcrew a.k.a adwisatya a.k.a xyberbreaker, wahyu_antijasakom
~ Cruz3N, mywisdom,flyff666, gunslinger_, ketek, chaer.newbie, petimati, gonzhack, spykit, xtr0nic, N4ck0, assadotcom, Qrembiezs, d4y4x, gendenk, si bD, Jimmy Deadc0de, Rede Deadc0de
~ All people in SMAN 3
~ All members of spyrozone
~ All members of echo
~ All members of newhack
~ All members of jatimcrew
~ All members of Anti-Jasakom
~ All members of whitecyber
~ All members of Devilzc0de
~ All members of Kaskus - "Especially Regional Solo Kaskus"
#e-c-h-o, #K-elektronik, #newhack, #Solohackerlink, #YF, #defacer, #manadocoding, #jatimcrew, #antijasakom, #whitecyber, #devilzc0de
---------------------------------------------------------------------------



Contact:
~~~~~~~~~
Shamus : Shamus@antijasakom.net
Homepage: https://antijasakom.net/forum/viewtopic.php?f=38&t=737
-------------------------------- [ EOF ] ----------------------------------
Visit this user's website Find all posts by this user
Quote this message in a reply
 Reputed by :  xtr0nic(+1)
06-14-2011, 06:52 AM
Post: #2
Mr.ping Offline
./Devilz Advisor
Posts: 605
Joined: Jul 2010
Reputation: 13
RE: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
ijin coba ya om mantap .....
ngacir
Find all posts by this user
Quote this message in a reply
06-14-2011, 06:53 AM
Post: #3
tukang.martabak.depan.kampus Offline
./Devilz Officer
Posts: 208
Joined: Apr 2011
Reputation: 4
RE: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
kayaknya bisa buat nyari duit neah om?? hmm hmm hmm hmm
Find all posts by this user
Quote this message in a reply
06-14-2011, 07:13 AM
Post: #4
Wayc0de Offline
-= Sifu Makan Sonice =-
**
Moderators
Posts: 2,981
Joined: Nov 2010
Reputation: 61
RE: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
lw pke dork "view_cart.php" and "view_product.php" mgkin bisa dpet $$ didalamnya hmm

nice share om,,, mantap
Visit this user's website Find all posts by this user
Quote this message in a reply
06-14-2011, 07:44 AM
Post: #5
p0pc0rn Offline
./Devilz Commander
Posts: 349
Joined: Feb 2011
Reputation: 53
RE: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
woh..masih ada bug dalam cubecart..
ga pernah free from bug untuk setiap versinya
Find all posts by this user
Quote this message in a reply
06-14-2011, 09:58 AM
Post: #6
castro Offline
./ Kimcil HunteR \.
Posts: 550
Joined: Feb 2011
Reputation: 27
RE: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
wahh iji belajar omz piss
singkat pada jelas wawa
Find all posts by this user
Quote this message in a reply
06-14-2011, 10:04 AM
Post: #7
panoya Offline
./Devilz Commander
Posts: 363
Joined: Apr 2010
Reputation: 3
RE: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
ane bookmark dolo ya ..

mantap
Find all posts by this user
Quote this message in a reply
06-14-2011, 10:08 AM
Post: #8
chaer.newbie Offline
--------------------------
*****
Dewa
Posts: 5,288
Joined: Dec 2009
Reputation: 184
RE: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
keren nih belajar
Find all posts by this user
Quote this message in a reply
06-14-2011, 10:18 AM
Post: #9
Sudden_death Away
0r4ng 94nt3ng
Posts: 412
Joined: Feb 2010
Reputation: 7
RE: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
keep share exploit om... belajar
Visit this user's website Find all posts by this user
Quote this message in a reply
06-14-2011, 10:37 AM
Post: #10
kurtz Offline
./Devilz Officer
Posts: 89
Joined: Feb 2010
Reputation: 1
RE: CubeCart 2.0.7 XSS && Remote SQL Injection => Multiple Vulnerabilities
nice share sob, mau icip2 dlu dugem
Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Pages (2): 1 2 Next »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Remote Stack Overflow Exploitation Tutorial - Exploiting Minalic Web Server 2 on x86 cr0security 0 83 05-05-2013 08:09 AM
Last Post: cr0security
  Bypassing ASLR During Remote Stack Overflow Exploitation on Linux - Method 1 cr0security 0 60 04-07-2013 11:26 AM
Last Post: cr0security
  #DiyWeb Admin Bypass dan Remote file/shell Upload exploit AnonymousOpsID 4 337 11-06-2012 05:07 PM
Last Post: rock_me
  [Tutor] Hotel Booking Portal v0.1 Multiple Vulnerabilities Reborn Of Code 9 342 10-30-2012 12:42 PM
Last Post: xnuxer_001
Star [Share] Remote PHP Shell Upload Vulnurabillity brianfahmi 9 348 10-27-2012 09:31 AM
Last Post: mariachi
  [Tutor] Sistem Biwes Multiple Vulnerability eidelweiss 10 260 09-01-2012 10:09 AM
Last Post: Super Moderator
  [Tutor] Joomla Component - com_filecabinet Vulnerable to SQL Injection p0pc0rn 11 543 07-29-2012 08:28 AM
Last Post: blackhariki
Bug CMS Schoolhos - Remote Arbitrary File Upload nuxbie_cyber 10 347 06-28-2012 06:47 PM
Last Post: Loex
Bug CMS DMS-Easy - Multiple Vulnerability nuxbie_cyber 6 166 06-23-2012 09:15 PM
Last Post: chiboga
Bug RevolutionTechnologies - SQL Injection Vulnerability nuxbie_cyber 6 220 06-14-2012 11:20 AM
Last Post: Anonymous33

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-26-2013, 01:21 AM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE