what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Quick.Cart / Quick.CMS XSRF

Quick.Cart / Quick.CMS XSRF
Posted Nov 24, 2009
Authored by Alice Kaerast

Quick.Cart version 3.4 and Quick.CMS version 2.4 both suffer from cross site request forgery vulnerabilities.

tags | exploit, vulnerability, csrf
SHA-256 | a291709208fa14adc1a5eab49ffc15c878c487a510f9d3913c92d128302ffe83

Quick.Cart / Quick.CMS XSRF

Change Mirror Download

Systems Affected: Quick.Cart 3.4 (other versions untested), Quick.CMS
2.4 (other versions untested)
Severity: Medium
Vendor: https://opensolution.org/
Author: Alice Kaerast

0. Timeline
25-10-2009 Vulnerability discovered
26-10-2009 Vendor contacted
23-11-2009 No response from vendor, report published

1. Background
Quick.Cart is a "freeware, simple and easy to use shopping cart script.
With this script you will be able to create products database and soon
you will be glad to recieve many orders from your customers."

Quick.CMS is a "freeware, fast and easy to customize Content Management
System. In few moments you will be able to add pages in different
languages and create your own web site."

Both products are used on a number of (mostly) Polish websites.

2. Description
There is a CSRF vulnerability in the delete functions of Quick.Cart and
Quick.CMS. Deleting products, pages and orders is done through an HTTP
GET function which although checked using javascript can be bypassed.

3. Proof of Concept
An attacker creates an html page which calls a delete function using an
img or iframe:

<img
src="https://opensolution.org/Quick.Cart/demo/admin.php?p=orders-delete&iOrder=2" />
<iframe
src="https://opensolution.org/Quick.Cms/demo_lite/admin.php?p=p-delete&iPage=1"></iframe>

The administrator of the vulnerable site then needs to visit this html
page whilst logged into his/her site.

4. Mitigation
The site administrator needs to be logged into the site and visit the
attacker-owned html page. If a site administrator never surfs the
internet whilst logged into his/her website then they are safe.

5. Detection
The Quick.Cart license states that all Quick.Cart-powered sites *must*
include the text "Powered by Quick.Cart" unless you pay to remove it.

The Quick.CMS license states that all Quick.CMS-powered sites *must*
include the text "Powered by Quick.CMS" unless you pay to remove it.

6. Vendor Response
The vendor acknowledged our request for a security contact but then
failed to acknowledge this vulnerability. We are therefore releasing
it to the wider community.

7. Acknowledgements
@agentrickard for assisting in fixing Drupal input formats so we can
actually display this announcement. James Clayton for pushing me to
test this software.

8. Legal Notices
Copyright (c) 2009 Computer Gentle

Permission is granted for the redistribution of this alert
electronically. It may not be edited in any way without my express
written consent. If you wish to reprint the whole or any part of this
alert in any other medium other than electronically, please email me
for permission.

Disclaimer: The information in the advisory is believed to be accurate
at the time of publishing based on currently available information. Use
of the information constitutes acceptance for use in an AS IS
condition. There are no warranties with regard to this information.
Neither the author nor the publisher accepts any liability for any
direct, indirect, or consequential loss or damage arising from use of,
or reliance on, this information.

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close