Avactis Shopping Cart Security Bypass and HTML Injection Vulnerabilities
18 Jul. 2012
Summary
Avactis Shopping Cart is prone to a security-bypass vulnerability and an HTML-injection vulnerability because it fails to properly validate user-supplied input.
Vulnerable Systems:
*Pentasoft Avactis Shopping Cart 1.9.1 and prior
An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
The attacker may leverage the security-bypass issue to bypass certain security restrictions and perform unauthorized actions in the affected application.
Vendor Status:
Currently we are not aware of any vendor-supplied patches