Praetorian503 Posted December 25, 2012 Report Posted December 25, 2012 CubeCart versions 4.4.6 and below suffer from multiple cross site scripting vulnerabilities.1. OVERVIEWCubeCart 4.4.6 and lower versions are vulnerable to Cross Site Scripting.2. BACKGROUNDCubeCart is an "out of the box" ecommerce shopping cart softwaresolution which has been written to run on servers that have PHP &MySQL support. With CubeCart you can quickly setup a powerful onlinestore which can be used to sell digital or tangible products to newand existing customers all over the world.3. VULNERABILITY DESCRIPTIONMultiple parameters are not properly sanitized, which allows attackerto conduct Cross Site Scripting attack. This may allow an attacker tocreate a specially crafted URL that would execute arbitrary scriptcode in a victim's browser.4. VERSIONS AFFECTED4.4.6 and lower5. Affected URLs and Parameters/admin.php (countiesPage parameter)/admin.php (countriesPage parameter)/admin.php (dStart parameter)/admin.php (edit parameter)/admin.php (email parameter)/admin.php (FCKeditor parameter)/admin.php (gc%5Bmax%5D parameter)/admin.php (gc%5Bmin%5D parameter)/admin.php (gc%5BproductCode%5D parameter)/admin.php (gc%5Bweight%5D parameter)/admin.php (gc[max] parameter)/admin.php (gc[min] parameter)/admin.php (gc[productCode] parameter)/admin.php (gc[weight] parameter)/admin.php (loc]/admin.php (page parameter)/admin.php (prod_master_id parameter)/admin.php (searchStr parameter)/admin.php (thumbName[] parameter)/admin.php (User-Agent HTTP header)/admin.php (yStart parameter)/index.php (Referer HTTP header)6. SOLUTIONThe CubeCart 4.x version family is no longer maintained by the vendor.Upgrade to the currently supported latest CubeCart version - 5.x.7. VENDORCubeCart Development Teamhttp://cubecart.com/8. CREDITAung Khant, http://yehg.net, YGN Ethical Hacker Group, Myanmar.9. DISCLOSURE TIME-LINE2012-12-22: CubeCart 4.x in End-of-Support/Maintenance circle2012-12-24: Vulnerability disclosed10. REFERENCESOriginal Advisory URL:http://yehg.net/lab/pr0js/advisories/%5Bcubecart_4.4.6%5D_xssCubeCart Home Page: http://cubecart.com/CubeCart Bug-Fix Announcement:http://forums.cubecart.com/topic/45456-cubecart-447-released/CubeCart4 End-of-Life Announcement:http://forums.cubecart.com/topic/46765-cubecart-v4-end-of-life-saturday-22-december/#yehg [2012-12-24]---------------------------------Best regards,YGN Ethical Hacker GroupYangon, Myanmarhttp://yehg.netOur Lab | http://yehg.net/labOur Directory | http://yehg.net/hwdSource: YGN Ethical Hacker Group :: Security Research Quote