![]() |
Security Questions on v4.7 |
Post Reply ![]() |
Author | ||||||
Scurit ![]() Newbie ![]() Joined: 29-April-2014 Location: Sarasota, FL Status: Offline Points: 3 |
![]() ![]() ![]() ![]() ![]() Posted: 29-April-2014 at 8:57pm |
|||||
I was recently contacted by a client that uses your system and has another party that regularly does Nessus vulnerability scans on their network/systems. This week then sent me some information and I verified that it was indeed valid -on their site. I was unable to reproduce the same result on your demo site which raises a few questions
![]() The first issue that was detected was a SQL Injection/information disclosure vulnerability in the opc_OrderVerify.asp, and when I followed the steps in the report, I was indeed able to reproduce and get the results in the report. it dumped out a debug of the following (not posting the "how", just the results):
The second item was a XSS vulnerability in the same file as well as the msgb.asp file (I won't post the details here either - you can msg me for that). I'm not an expert on ProductCart by any means - just security with a background in classic asp. What I would like to know is, is it possible there is a debug feature that needs to be turned off somewhere in one of the asp files (which I didn't see in the demo admin screens) and how could their site have a XSS vulnerability and the demo site not show the same behavior if they are running the same version? Server script/security settings possibly? Can you tell me anything else that might affect their system and make it act differently than your demo? Thanks in advance! |
||||||
![]() |
||||||
Matt ![]() Moderator Group ![]() Joined: 20-July-2006 Location: United States Status: Offline Points: 73 |
![]() ![]() ![]() ![]() ![]() |
|||||
Yes, that is exactly correct. There is a debug variable that is probably commented out.
Can you open a ticket to continue this conversation since it may involve sensitive information? |
||||||
![]() |
||||||
Scurit ![]() Newbie ![]() Joined: 29-April-2014 Location: Sarasota, FL Status: Offline Points: 3 |
![]() ![]() ![]() ![]() ![]() |
|||||
I don't have their license number at this time, can I still create a ticket?
|
||||||
![]() |
||||||
Greg Dinger ![]() Certified ProductCart Developers ![]() ![]() Joined: 23-September-2006 Location: United States Status: Offline Points: 238 |
![]() ![]() ![]() ![]() ![]() |
|||||
I would recommend writing to them at info AT productcart.com
|
||||||
![]() |
Post Reply ![]() |
|
Tweet
|
Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |