<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CubeCart 4 session management bypass leads to administrator access</title>
	<atom:link href="http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/</link>
	<description>Acunetix Web Application Security Blog</description>
	<lastBuildDate>Fri, 10 Feb 2012 07:58:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Acunetix Web Application Security Blog » CubeCart 4 session &#8230; &#124; Coder Online</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-3355</link>
		<dc:creator>Acunetix Web Application Security Blog » CubeCart 4 session &#8230; &#124; Coder Online</dc:creator>
		<pubDate>Mon, 18 Jan 2010 21:32:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-3355</guid>
		<description>[...] Read this article: Acunetix Web Application Security Blog » CubeCart 4 session &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] Read this article: Acunetix Web Application Security Blog » CubeCart 4 session &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CubeCart neglect to inform their customers of critical vulnerability &#124; Online Payment Solutions</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-3018</link>
		<dc:creator>CubeCart neglect to inform their customers of critical vulnerability &#124; Online Payment Solutions</dc:creator>
		<pubDate>Tue, 05 Jan 2010 06:21:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-3018</guid>
		<description>[...] installing modules and so on. You can find a detailed description of the vulnerability on the Acunetix blog including a proof of [...]</description>
		<content:encoded><![CDATA[<p>[...] installing modules and so on. You can find a detailed description of the vulnerability on the Acunetix blog including a proof of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nodo54 &#187; Blog Archive &#187; CubeCart 4 session management bypass leads to administrator access</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-2602</link>
		<dc:creator>Nodo54 &#187; Blog Archive &#187; CubeCart 4 session management bypass leads to administrator access</dc:creator>
		<pubDate>Wed, 25 Nov 2009 05:57:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-2602</guid>
		<description>[...] Proof of concept and more info: http://www.acunetix.com/blog/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Proof of concept and more info: <a href="http://www.acunetix.com/blog/" rel="nofollow">http://www.acunetix.com/blog/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CubeCart 4 security vulnerability: is your store at risk? &#124; frag (frăg)</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-2467</link>
		<dc:creator>CubeCart 4 security vulnerability: is your store at risk? &#124; frag (frăg)</dc:creator>
		<pubDate>Wed, 04 Nov 2009 16:06:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-2467</guid>
		<description>[...] reading on XSS attacks today, I found this recently reported exploint in CubeCart 4 that can gain you administrative access to the [...]</description>
		<content:encoded><![CDATA[<p>[...] reading on XSS attacks today, I found this recently reported exploint in CubeCart 4 that can gain you administrative access to the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Warning to anyone running CubeCart - Irish SEO, Marketing &#38; Webmaster Discussion</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-2441</link>
		<dc:creator>Warning to anyone running CubeCart - Irish SEO, Marketing &#38; Webmaster Discussion</dc:creator>
		<pubDate>Mon, 02 Nov 2009 11:54:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-2441</guid>
		<description>[...] for administrator users in CubeCart. You can find full details of the vulnerability on the Acunetix blog. Basically you could by-pass the session management and get full administrator access to any [...]</description>
		<content:encoded><![CDATA[<p>[...] for administrator users in CubeCart. You can find full details of the vulnerability on the Acunetix blog. Basically you could by-pass the session management and get full administrator access to any [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan Calin</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-2440</link>
		<dc:creator>Bogdan Calin</dc:creator>
		<pubDate>Mon, 02 Nov 2009 11:23:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-2440</guid>
		<description>Thanks Dave. I will update the story to mention that CubeCart responded and published information about this vulnerability. Thanks again.</description>
		<content:encoded><![CDATA[<p>Thanks Dave. I will update the story to mention that CubeCart responded and published information about this vulnerability. Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Lowry</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-2437</link>
		<dc:creator>Dave Lowry</dc:creator>
		<pubDate>Mon, 02 Nov 2009 09:50:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-2437</guid>
		<description>Hi Bogdan,

Great work on finding this vulnerability and documenting it so well. I did a blog post about the vulnerability after reading your post.

&lt;a href=&quot;http://www.webpayments.ie/blog/cubecart-neglect-to-inform-their-customers-of-critical-vulnerability.html&quot; title=&quot;CubeCart neglect to inform their customers of a critical vulnerability&quot; rel=&quot;nofollow&quot;&gt; CubeCart neglect to inform their customers of a critical vulnerability&lt;/a&gt;

CubeCart have &lt;a href=&quot;http://www.webpayments.ie/blog/cubecart-neglect-to-inform-their-customers-of-critical-vulnerability.html#comment-83&quot; title=&quot;CubeCart make formal apology on webpayments.ie&quot; rel=&quot;nofollow&quot;&gt;since responded and made a formal apology on my site.&lt;/a&gt;

They also posted an apology and notification on their site. I do not think this makes things right but hopefully it will help notify there customers of the problem.

Thanks,
Dave</description>
		<content:encoded><![CDATA[<p>Hi Bogdan,</p>
<p>Great work on finding this vulnerability and documenting it so well. I did a blog post about the vulnerability after reading your post.</p>
<p><a href="http://www.webpayments.ie/blog/cubecart-neglect-to-inform-their-customers-of-critical-vulnerability.html" title="CubeCart neglect to inform their customers of a critical vulnerability" rel="nofollow"> CubeCart neglect to inform their customers of a critical vulnerability</a></p>
<p>CubeCart have <a href="http://www.webpayments.ie/blog/cubecart-neglect-to-inform-their-customers-of-critical-vulnerability.html#comment-83" title="CubeCart make formal apology on webpayments.ie" rel="nofollow">since responded and made a formal apology on my site.</a></p>
<p>They also posted an apology and notification on their site. I do not think this makes things right but hopefully it will help notify there customers of the problem.</p>
<p>Thanks,<br />
Dave</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan Calin</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-2436</link>
		<dc:creator>Bogdan Calin</dc:creator>
		<pubDate>Mon, 02 Nov 2009 09:45:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-2436</guid>
		<description>Charlie, this problem is very real. I don&#039;t know why you cannot reproduce it.
This problem was initially reported to them (CubeCart) and after it was fixed (in 4.3.5), it was published on this blog. So, they reproduced and fixed the problem.</description>
		<content:encoded><![CDATA[<p>Charlie, this problem is very real. I don&#8217;t know why you cannot reproduce it.<br />
This problem was initially reported to them (CubeCart) and after it was fixed (in 4.3.5), it was published on this blog. So, they reproduced and fixed the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charlie Smi</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-2423</link>
		<dc:creator>Charlie Smi</dc:creator>
		<pubDate>Sun, 01 Nov 2009 17:19:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-2423</guid>
		<description>We are unable to verifiy this problem. Perhaps that is why it was not listed in the changelog?</description>
		<content:encoded><![CDATA[<p>We are unable to verifiy this problem. Perhaps that is why it was not listed in the changelog?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: News CubeCart 4 session management bypass leads to administrator access &#124; Web 2.0 Designer</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-2390</link>
		<dc:creator>News CubeCart 4 session management bypass leads to administrator access &#124; Web 2.0 Designer</dc:creator>
		<pubDate>Fri, 30 Oct 2009 10:12:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-2390</guid>
		<description>[...] Read the original post: CubeCart 4 session management bypass leads to administrator access [...]</description>
		<content:encoded><![CDATA[<p>[...] Read the original post: CubeCart 4 session management bypass leads to administrator access [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uberVU - social comments</title>
		<link>http://www.acunetix.com/blog/news/cubecart-4-session-management-bypass-leads-to-administrator-access/#comment-2389</link>
		<dc:creator>uberVU - social comments</dc:creator>
		<pubDate>Fri, 30 Oct 2009 09:48:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.acunetix.com/blog/?p=801#comment-2389</guid>
		<description>&lt;strong&gt;Social comments and analytics for this post...&lt;/strong&gt;

This post was mentioned on Twitter by seanmw: RT @ethicalhack3r: (shopping cart used by over a million stores worldwide) session management bypass vulnerability; http://bit.ly/PyyZn...</description>
		<content:encoded><![CDATA[<p><strong>Social comments and analytics for this post&#8230;</strong></p>
<p>This post was mentioned on Twitter by seanmw: RT @ethicalhack3r: (shopping cart used by over a million stores worldwide) session management bypass vulnerability; <a href="http://bit.ly/PyyZn.." rel="nofollow">http://bit.ly/PyyZn..</a>.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

