JSEMTS搜尋引擎
 

From: "S-Quadra Security Research"
To: "bugtraq" ; "full-disclosure"
Subject: CactuSoft CactuShop v5.x shopping cart software multiple security vulnerabilities
Date: Wednesday, March 31, 2004 9:54 PM

S-Quadra Advisory #2004-03-31

Topic: CactuSoft CactuShop v5.x shopping cart software multiple security
vulnerabilities
Severity: High
Vendor URL: http://www.cactushop.com
Advisory URL: http://www.s-quadra.com/advisories/Adv-20040331.txt
Release date: 31 Mar 2004

1. DESCRIPTION

CactuShop is an ASP application for running an e-commerce web site. It
incorporates a databased catalogue system, front end pages for product
navigation, back end pages for updating product details and robust
basket code for memorizing product selections as a visitor moves around
the web site. ASP software is designed to run on a Microsoft NT or Win
2000 server and to use MS Access, MS SQL Server or MySQL as a backend.
Please visit http://www.cactushop.com for information about CactuShop
shopping cart.

2. DETAILS

-- Vulnerability 1: SQL Injection vulnerability

An SQL Injection vulnerability has been found in following scripts :
'mailorder.asp' and 'payonline.asp'. User supplied input parameter is
'strItems' not filtered before being used in an SQL query. Thus the
query modification through malformed input is possible.

Successful exploitation of this vulnerability can enable an attacker
to execute commands in the system (via MS SQL xp_cmdshell function).

-- Vulnerability 2: Cross Site Scripting vulnerability found in
'largeimage.asp'script

By injecting specially crafted javascript code in url and tricking a
user to visit it a remote attacker can steal user session id and gain
access to user's personal data.

--PoC code

--Vulnerability 1:

Platform: MS SQL Server as a backend

Posting this data to 'payonline.asp' executes 'dir c:' command

strAgain=yes&CD_EmailAddress=dummy@someemailservice.com&CD_Password=&
CD_AffiliateID=&CD_CardholderCountry=200&CD_ShippingCountry=200&
CD_ShippingPostcode=&strPaymentSystem=email&CP_CouponCode=&numLanguageID=1&
numCurrencyID=1&numItemCount=2&strItems=214;+exec+master..xp_cmdshell+'dir+c:'--z165z&
strQuantities=6z2z&numShipMethod=1&btnProceed=Proceed

-- Vulnerability 2:

http://[target]/popuplargeimage.asp?strImageTag=

3. FIX INFORMATION

11 Mar 2004: S-Quadra alerted CactuSoft (CactuShop developers) on these
issues.
15 Mar 2004: CactuSoft response:

"1) SQL Injection

On payonline.asp and all mailorder pages the strItems field is now
parsed for single-quote (') characters before being used with database
queries. Single quotes are escaped (replaced with 2 single-quotes) to
ensure SQL Injection won't work.

2) Javascript Injection

The strImageTag field is parse for HTML tags characters (< and >) and
are removed from the string. This should ensure against






搜尋引擎讓我們程式搜尋結果更加完美
  • 如果您覺得該文件有幫助到您,煩請按下我
  • 如果您覺得該文件是一個一無是處的文件,也煩請按下我

  • 搜尋引擎該文件您看起來是亂碼嗎?您可以切換編碼方式試試看!ISO-8859-1 | latin1 | euc-kr | euc-jp | CP936 | CP950 | UTF-8 | GB2312 | BIG5 |
    搜尋引擎本文件可能涉及色情、暴力,按我申請移除該文件

    搜尋引擎網址長?按我產生分享用短址

    ©2026 JSEMTS

    https://tw.search.yahoo.com/search;_ylt=A8tUwYgkQU1YcXoAUE9r1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC10dwRncHJpZAMxWU5tY2FYMVFGQ2ZvUXZGN1N0bzVBBG5fcnNsdAMwBG5fc3VnZwMwBG9yaWdpbgN0dy5zZWFyY2gueWFob28uY29tBHBvcwMwBHBxc3RyAwRwcXN0cmwDBHFzdHJsAzQ4BHF1ZXJ5AyVFNiVBRCVBMSVFNiVBRCU4QyUyMCVFNSVCMCU4OCVFNiU4MyU4NSVFNSU5QyU5OAR0X3N0bXADMTQ4MTQ1Nzk3Ng--?p=%E6%AD%A1%E6%AD%8C+%E5%B0%88%E6%83%85%E5%9C%98&fr2=sb-top-tw.search&fr=yfp-t-900-tw&rrjfid=5781792 https://tw.search.yahoo.com/search;_ylt=A8tUwYgkQU1YcXoAUE9r1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC10dwRncHJpZAMxWU5tY2FYMVFGQ2ZvUXZGN1N0bzVBBG5fcnNsdAMwBG5fc3VnZwMwBG9yaWdpbgN0dy5zZWFyY2gueWFob28uY29tBHBvcwMwBHBxc3RyAwRwcXN0cmwDBHFzdHJsAzQ4BHF1ZXJ5AyVFNiVBRCVBMSVFNiVBRCU4QyUyMCVFNSVCMCU4OCVFNiU4MyU4NSVFNSU5QyU5OAR0X3N0bXADMTQ4MTQ1Nzk3Ng--?p=%E6%AD%A1%E6%AD%8C+%E5%B0%88%E6%83%85%E5%9C%98&fr2=sb-top-tw.search&fr=yfp-t-900-tw&rrjfid=9486219 https://tw.search.yahoo.com/search;_ylt=A8tUwYgkQU1YcXoAUE9r1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC10dwRncHJpZAMxWU5tY2FYMVFGQ2ZvUXZGN1N0bzVBBG5fcnNsdAMwBG5fc3VnZwMwBG9yaWdpbgN0dy5zZWFyY2gueWFob28uY29tBHBvcwMwBHBxc3RyAwRwcXN0cmwDBHFzdHJsAzQ4BHF1ZXJ5AyVFNiVBRCVBMSVFNiVBRCU4QyUyMCVFNSVCMCU4OCVFNiU4MyU4NSVFNSU5QyU5OAR0X3N0bXADMTQ4MTQ1Nzk3Ng--?p=%E6%AD%A1%E6%AD%8C+%E5%B0%88%E6%83%85%E5%9C%98&fr2=sb-top-tw.search&fr=yfp-t-900-tw&rrjfid=1176757 https://tw.search.yahoo.com/search;_ylt=A8tUwYgkQU1YcXoAUE9r1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC10dwRncHJpZAMxWU5tY2FYMVFGQ2ZvUXZGN1N0bzVBBG5fcnNsdAMwBG5fc3VnZwMwBG9yaWdpbgN0dy5zZWFyY2gueWFob28uY29tBHBvcwMwBHBxc3RyAwRwcXN0cmwDBHFzdHJsAzQ4BHF1ZXJ5AyVFNiVBRCVBMSVFNiVBRCU4QyUyMCVFNSVCMCU4OCVFNiU4MyU4NSVFNSU5QyU5OAR0X3N0bXADMTQ4MTQ1Nzk3Ng--?p=%E6%AD%A1%E6%AD%8C+%E5%B0%88%E6%83%85%E5%9C%98&fr2=sb-top-tw.search&fr=yfp-t-900-tw&rrjfid=5297851 https://tw.search.yahoo.com/search;_ylt=A8tUwYgkQU1YcXoAUE9r1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC10dwRncHJpZAMxWU5tY2FYMVFGQ2ZvUXZGN1N0bzVBBG5fcnNsdAMwBG5fc3VnZwMwBG9yaWdpbgN0dy5zZWFyY2gueWFob28uY29tBHBvcwMwBHBxc3RyAwRwcXN0cmwDBHFzdHJsAzQ4BHF1ZXJ5AyVFNiVBRCVBMSVFNiVBRCU4QyUyMCVFNSVCMCU4OCVFNiU4MyU4NSVFNSU5QyU5OAR0X3N0bXADMTQ4MTQ1Nzk3Ng--?p=%E6%AD%A1%E6%AD%8C+%E5%B0%88%E6%83%85%E5%9C%98&fr2=sb-top-tw.search&fr=yfp-t-900-tw&rrjfid=1849500 https://tw.search.yahoo.com/search;_ylt=A8tUwZJ2QE1YaVcAUmFr1gt.;_ylc=X1MDMjExNDcwNTAwMwRfcgMyBGZyA3lmcC10LTkwMC1zLXR3BGdwcmlkAwRuX3JzbHQDMARuX3N1Z2cDMARvcmlnaW4DdHcuc2VhcmNoLnlhaG9vLmNvbQRwb3MDMARwcXN0cgMEcHFzdHJsAwRxc3RybAM4NARxdWVyeQMlRTglQjYlODUlRTUlOEYlQUYlRTYlODQlOUIlRTclOUElODQlRTUlQUYlQjYlRTUlQUYlQjYlMjAlRTglODMlQTElRTUlQUUlODklRTUlQTglOUMEdF9zdG1wAzE0ODE0NTc3OTM-?p=%E8%B6%85%E5%8F%AF%E6%84%9B%E7%9A%84%E5%AF%B6%E5%AF%B6+%E8%83%A1%E5%AE%89%E5%A8%9C&fr2=sb-top-tw.search&fr=yfp-t-900-s-tw&rrjfid=6387261 buy.gamer[前往][前往]emag.hu[前往]adidas[前往]tku.fandomMomo365cyunshop[前往]9438jgw528shufaiiMamaclub[前往][前往]DS-HKScdmtj[前往][教學] VeraCrypt 指令ups[前往][前往]sesodahousethornwikiparklanehttp://samsung.healths.com.tw/?site=1haoowizzardsblog1046000ziyuanericdataec.elifemallhttps://archivestar.hostfree.cyou/taro1985歸檔星球80tt1Myth1lZohopublicprrpc[前往]buzzorangeYxwst58leechi[前往]X7cq[前往][資訊] 詭異的電話號碼[前往]kiss99歸檔星球[技術] Word 2007在Win 10出現記憶體不足問題解決xjj1DmhgJSEMTS資料收集器軟體相關資料、序號搜尋digitimes[前往]newhopefoodCarrdWebNodeSo0912hmly666[前往]edrv[教學] 系統還原出現錯誤0X81000203解決[教學] JavaScript速查wwwcreativeFans17[前往][前往]eliteracy[前往]plain-me[前往]OptionSharemyhousingwiki[前往]bankchb[前往]howhiteLineage2twgandi[前往][前往]歸檔星球zingalaFirstoryglobal3cStatic.Appnordvpn9x9ntpugift.colazblackbridge[前往]Brockca[前往]fdbbscwbookyamcasetify[前往][前往][前往]priorGuelphchinesegztongchengti[教學] 以色列屠殺加薩走廊真相moredigitalNew3lunchNew182Jiaoyitruu[分享] 12星座永不會變的9個特質[前往]law.mojtrihce[前往]studentBVW批次網站伺服器BVW批次網站伺服器(BATCH VBSCRIPT WEBSERVER)youngnews3631sugar8[前往][前往]travel.yamhxwltworbisjingjincloud[前往]aversi.ge[前往]Taishacatchplay基督生命堂基督生命堂[前往][前往][前往]gu-globalBc3ts[教學] OFFICE 201X 啟動跳出365啟用畫面megabank[前往]twn.mizuno[前往][技術] 筆電加速開機,Lenovo IdeaPad L340Gamerofiii[前往]tiktokuwanwavenet[教學] PUBG 閃退(絕地求生)解決方案casiosanlien[資訊] 專情團[教學] Chrome解決CORS問題gj.aizhancde[前往]Anzforum[前往]mart.familydfd.video.nchuamtopblogdomagoline[教學] 讓生命強制延長20年Aeustthink3ccm-petdjwxnccu.primo.exlibrisgroup[前往][教學] 禁用密碼清單shouxishecopilot.microsoftpkthinkitqulouisvuitton[技術] N網的「神的語言」現象研究:二次元數位社群中的符號實踐與文化認同[前往]airbnb[前往][前往]Xiuwushidaityciis104[前往][前往][前往]logitech[教學] 關閉打開IE瀏覽器強制跳轉EDGE瀏覽器[教學] 停用WINDOWS更新方式emshosttaichungdarkml[科技] HTTPS部分網站無法瀏覽fg.tp[前往]neutrallowikiversityTianranju0752snywfilm-supplysenheyuanStrikingly[前往]yomixTenda-teamthinkwithgoogletcb[前往][前往]jzn[前往][教學] 台男悲歌2022greenpeacecontrelUnitehkgzpuXlsq17amazon[前往][前往]專情團專情團官方網站ticl[前往]dbblackporkes-designsitesearch.openfindIS[教學] 寄件者政策框架SPF[前往]anime1erbPCloud[前往]歸檔星球[教學] 線上Port掃描工具[技術] Chrome 書籤救回、使用者設定檔誤刪除http://kserver3.asuscomm.com/[前往][資訊] 阿彌陀佛[教學] 台灣疑似已被駭客入侵的網站列表(domain2multi-tw)SytesPchome[前往]paintingsofdecayChip123[前往][分享] Arduino常用函數2345enywp.kmusearchopentextYunduost[前往]Bit[教學] 林襄暗網流出私密影片xuyi365thebodyshop[前往]search.yahooeasyrent[前往]Ninini573r168gamesfhktdcKy58gloria-eyewearipcf[教學] 顯示卡高階、中階與低階分級量表(2022)tcuvipputer-twcustomsChatGPTAbcvote[前往][技術] Chrome瀏覽器使用公共解析Public DNShome.gamerxexymix[前往]OnlineHost[教學] 下雪特效專情の團員作品精選專情の團員作品精選 parentingliteracy[前往][前往]996tea[前往]ThreadslingyetrainingdungdongGotoMaxLineage66[技術] LibreOffice卡頓問題解決unipet[前往]sfworldwideboseIT TOP Blog