J-Security Center

Title: osCommerce Multiple HTTP Response Splitting Vulnerabilities

Severity: MODERATE

Description:

osCommerce is an open-source PHP e-commerce suite.

osCommerce is prone to multiple HTTP response splitting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

The problem presents itself when an attacker sends malicious input to the application via the 'buy now' button in the product listings and review page. Apparently the application fails to properly sanitize the input prior to using it to load dynamic content. The same problem applies to the 'cust_order' parameter, however a user needs to be currently logged in to the application to access that action. This issue also affects the 'goto' parameter of 'banner.php'; other scripts and parameters may also be affected.

A remote attacker may exploit any of these vulnerabilities to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.

Affected Products:

  • osCommerce osCommerce 2.1.0
  • osCommerce osCommerce 2.2.0 cvs
  • osCommerce osCommerce 2.2.0 ms1
  • osCommerce osCommerce 2.2.0 ms2

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.