pedala1 Posted December 25, 2012 Report Posted December 25, 2012 1. OVERVIEWThe CubeCart 4.4.6 and lower versions are vulnerable to SQL Injection.2. BACKGROUNDCubeCart is an "out of the box" ecommerce shopping cart softwaresolution which has been written to run on servers that have PHP &MySQL support. With CubeCart you can quickly setup a powerful onlinestore which can be used to sell digital or tangible products to newand existing customers all over the world.3. VULNERABILITY DESCRIPTIONMultiple parameters are not properly sanitized, which allows attackerto conduct SQL Injection attack. This could an attacker to inject ormanipulate SQL queries in the back-end database, allowing for themanipulation or disclosure of arbitrary data.4. VERSIONS AFFECTED4.4.6 and lower5. Affected URLs and Parameters/admin.php (active parameter)/admin.php (cat_id parameter)/admin.php (orderCol parameter)/admin.php (orderDir parameter)6. SOLUTIONThe CubeCart 4.x version family is no longer maintained by the vendor.Upgrade to the currently supported latest CubeCart version - 5.x.7. VENDORCubeCart Development TeameCommerce Software | CubeCart8. CREDITAung Khant, YGN Ethical Hacker Group :: Security Research, YGN Ethical Hacker Group, Myanmar.9. DISCLOSURE TIME-LINE2012-12-22: CubeCart 4.x in End-of-Support/Maintenance circle2012-12-24: Vulnerability disclosedSursa: CubeCart 4.4.6 SQL Injection ? Packet Storm Quote