TUCoPS :: Web :: e-commerce, shopping carts :: bt1436.txt

Xpressions Software: Multiple SQL Injection Attacks To Manage WebStore

Xpressions Software : Multiple SQL Injection Attacks To
Manage WebStore(s).


No user supplied data is correctly parsed for SQL queries before being
execuited and thus allows for an attacker inject his/her own queries in
any user supplied post data.
A more direct and dangerous attack however can be taken at the
administration page.
User: admin
Pass: ' or '1' = '1

This would allow the attacker to fully manage the site with admin
This exploit is found in every product they make.

The severity of this increases since no cryptography is used when
storing senstive data such as other users passwords and credit card
data, leaving them all in plaintext and in clear view of our attacker.

Company Status:
Company was contacted, no reply was given.

Suggestions/Work Arounds:
Move/htauth the manage directory, uninstall!

Paul Craig
Security Researcher
Pimp Industries

