Eazy Cart admin/home/index.php authentication bypass
| eazycart-admin-authentication-bypass (29419) |
Description:
Eazy Cart is vulnerable to authentication bypass. The default setting for administrative users only requires a password at login and does not prompt for password entry to perform specific administrative tasks. A local attacker could use an open administrative session to gain unauthorized access to all the administrative functions by accessing the admin/home/index.php file, which could allow the attacker to perform unauthorized administrative tasks in Eazy Cart
Platforms Affected:
- Eazy Cart, Eazy Cart
Remedy:
No remedy available as of July 4, 2009.
Consequences:
Bypass Security
References:
- Full-Disclosure Mailing List, Mon Oct 09 2006 - 20:22:41 CDT, MHL-2006-001 Public Advisory: "Eazy Cart" Multiple Security Issues at http://archives.neohapsis.com/archives/fulldisclosure/2006-10/0155.html.
- PHP Shopping Cart Software Web site, Eazy Cart - the Easy to Install Shopping Cart System at http://www.eazycart.com/.
- BID-20423: Eazy Cart Multiple Input Validation and Authentication Bypass Vulnerabilities
- CVE-2006-5245: Eazy Cart allows remote attackers to bypass authentication and gain administrative access via a direct request for admin/home/index.php, and possibly other PHP scripts under admin/.
- SA22286: Eazy Cart Multiple Vulnerabilities
- SECTRACK ID: 1017041: Eazy Cart Bugs Let Remote Users Gain Administrative Access, Modify Prices, and Conduct Cross-Site Scripting Attacks
Reported:
Oct 10, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
