Jump to content
pedala1

CubeCart 4.4.6 Local File Inclusion

Recommended Posts

Posted

1. OVERVIEW

CubeCart 4.4.6 and lower versions are vulnerable to Local File Inclusion.

2. BACKGROUND

CubeCart is an "out of the box" ecommerce shopping cart software

solution which has been written to run on servers that have PHP &

MySQL support. With CubeCart you can quickly setup a powerful online

store which can be used to sell digital or tangible products to new

and existing customers all over the world.

3. VULNERABILITY DESCRIPTION

CubeCart 4.4.6 and lower versions contain a flaw that may allow a

remote attacker to execute arbitrary commands or code. The issue is

due to the '/admin.php' script not properly sanitizing user input,

specifically directory traversal style attacks (e.g., ../../) supplied

to the 'loc' parameter. This may allow an attacker to include a file

from the targeted host that contains arbitrary commands or code that

will be executed by the vulnerable script. Such attacks are limited

due to the script only calling files already on the target host. In

addition, this flaw can potentially be used to disclose the contents

of any file on the system accessible by the web server.

4. VERSIONS AFFECTED

4.4.6 and lower

5. Affected URL and Parameter

/admin.php (loc parameter)

/admin.php?_g=filemanager/language&loc=/../../../public_ftp/uploads/hack.inc.php

6. SOLUTION

The CubeCart 4.x version family is no longer maintained by the vendor.

Upgrade to the currently supported latest CubeCart version - 5.x.

7. VENDOR

CubeCart Development Team

eCommerce Software | CubeCart

8. CREDIT

Aung Khant, YGN Ethical Hacker Group :: Security Research, YGN Ethical Hacker Group, Myanmar.

9. DISCLOSURE TIME-LINE

2012-12-22: CubeCart 4.x in End-of-Support/Maintenance circle

2012-12-24: Vulnerability disclosed

Sursa: CubeCart 4.4.6 Local File Inclusion ? Packet Storm

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...