Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » osCommerce plain text HTTP authentication

osCommerce plain text HTTP authentication

by Mario Miri on April 25th, 2003 osCommerce uses plain text HTTP protocol for authentication. An attacker could exploit this feature by spoofing the header and use this information for further attacks.


Vulnerable:
osCommerce 2.2 cvs


Solution:
Currently there are no vendor supplied patches.


Discovered by:
Lorenzo Hernandez Garcia-Hierro, [email protected]


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »