[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] CSC-Cart RCE - CVE-2017-15673



<html><head></head><body><div style="font-family: Verdana;font-size: 
12.0px;"><div>**** Summary</div>

<div>&nbsp;</div>

<div>CSC Cart is a PHP based shopping cart software, which is hosted either 
locally or by the company csc-cart company. It has a&nbsp;vulnerability in the 
administration section, which allows full remote code execution on the 
server.</div>

<div>&nbsp;</div>

<div>This has been allcoated CVE-2017-15673</div>

<div><br/>
&nbsp;**** Vendor of Product<br/>
&nbsp;<a 
data-saferedirecturl="https://www.google.com/url?hl=en-GB&amp;q=http://cs-cart.com&amp;source=gmail&amp;ust=1511519539231000&amp;usg=AFQjCNGu7QyGcGVsGNGDmJ2JKS-kuTxAew";
 href="http://cs-cart.com/"; rel="noreferrer" 
target="_blank">cs-cart.com</a><br/>
<br/>
<br/>
<br/>
&nbsp;**** Affected Product Code Base<br/>
&nbsp;CS-Cart - 4.6.2 and Some Previous<br/>
<br/>
<br/>
<br/>
&nbsp;**** Attack Vectors</div>

<div><br/>
&nbsp;A custom page can be created as part of the files function in the<br/>
&nbsp;administration section. It is possible to give this page a .php<br/>
&nbsp;filetype and fill it with valid php code. This can then be saved in a<br/>
&nbsp;location which allows the pages to be executed as php, therefore<br/>
&nbsp;gaining access to the whole server.<br/>
<br/>
&nbsp;</div></div></body></html>
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/