Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> General >> osCommerce Malformed Session ID XSS Vulnerability


Vulnerability Assessment Details

osCommerce Malformed Session ID XSS Vulnerability

Vulnerability Assessment Summary
Detect osCommerce Malformed Session ID XSS

Detailed Explanation for this Vulnerability Assessment

osCommerce is an online shop e-commerce solution under on going development
by the open source community. Its feature packed out-of-the-box installation
permits store owners to setup, run, and maintain their online stores with
minimum effort and with absolutely no costs or license fees involved.

osCommerce is vulnerable to a XSS flaw. The flaw can be exploited when a
malicious user passes a malformed session ID to URI.

Solution :
This is the response from the developer. To fix the issue, the $_sid parameter
needs to be wrapped around tep_output_string() in the tep_href_link() function
defined in includes/functions/html_output.php.

Before:
if (isset($_sid)) {
$link .= $separator . $_sid

}

After:
if (isset($_sid)) {
$link .= $separator . tep_output_string($_sid)

}

osCommerce 2.2 Milestone 3 will redirect the user to the index page when
a malformed session ID is used, so that a new session ID can be generated.

Network Security Threat Level: Medium

Networks Security ID: 9238

Vulnerability Assessment Copyright: This script is Copyright (C) 2003 Noam Rathaus

Cables, Connectors

DELL POWEREDGE R720 8B 2.5 SERVER TWO E5-2667 2.90GHZ 24GB 2 X 1TB SATA H310
$1409.0
DELL POWEREDGE R720 8B 2.5 SERVER TWO E5-2667 2.90GHZ 24GB 2 X 1TB SATA H310 pictureHP Z620 WORKSTATION W7 PRO TWO E5-2687WV2 3.4GHZ 96GB 2 X 1TB SATA NVS315 1GB
$2499.0
HP Z620 WORKSTATION W7 PRO TWO E5-2687WV2 3.4GHZ 96GB 2 X 1TB SATA NVS315 1GB pictureLenovo T420 i5 2.60GHz 6GB RAM 1TB HDD Windows 10 Laptop Notebook Computer
$249.99
Lenovo T420 i5 2.60GHz 6GB RAM 1TB HDD Windows 10 Laptop Notebook Computer pictureApple MC812LL/A Intel Core i5-2500S 4GB 1TB, Silver (Scratch and Dent)
$655.68
Apple MC812LL/A Intel Core i5-2500S 4GB 1TB, Silver (Scratch and Dent) picture


Discussions

No Discussions have been posted on this vulnerability.