[ advisories | exploits | discussions | news | conventions | security tools | texts & papers ]
 main menu
- feedback
- advertising
- privacy
- FightAIDS
- newsletter
- news
 
 discussions
- read forum
- new topic
- search
 

 meetings
- meetings list
- recent additions
- add your info
 
 top 100 sites
- visit top sites
- sign up now
- members
 
 webmasters

- add your url
- add domain
- search box
- link to us

 
 projects
- our projects
- free email
 
 m4d network
- security software
- secureroot
- m4d.com
Home : Advisories : Price modification in Element InstantShop

Title: Price modification in Element InstantShop
Released by: Securax
Date: 23rd October 2000
Printable version: Click here
=====================================================================

Securax-SA-07 Security Advisory

belgian.networking.security Dutch

=====================================================================

Topic: Price modification in Element InstantShop

Announced: 2000-10-23

Updated: 2000-10-23

O/S: Microsoft Windows NT 4 Server

Severity: High - Price modification possible

vendor URL: www.element.be

cgi-bin: /[bin-dir]/add_2_basket.asp

=====================================================================



THE INFORMATION CONTAINED IN THIS ADVISORY IS BELIEVED TO BE

ACCURATE AT THE TIME OF PRINTING, BUT NO REPRESENTATION OR WARRANTY

IS GIVEN, EXPRESS OR IMPLIED, AS TO ITS ACCURACY OR COMPLETENESS.

NEITHER THE AUTHOR NOR THE PUBLISHER ACCEPTS ANY LIABILITY

WHATSOEVER FOR ANY DIRECT, INDIRECT OR CONSEQUENTIAL LOSS OR DAMAGE

ARISING IN ANY WAY FROM ANY USE OF, OR RELIANCE PLACED ON, THIS

INFORMATION FOR ANY PURPOSE.







I. Background

It is possible to modify the unit price of items as it is submitted

as a hidden field as part of the order form. By saving a copy of

the order form down locally and modify the value it is possible to

submit a order form with a zero or even negative price value.







II. Impact

Example:







--> change value this to anything you like.













III. Recommendation

The vendor has been informed, but in the meanwhile we recommend

using non-realtime transactions ( ie: manual authorisation ). And

pay attention for a BMW going over the counter for $10 :-)







IV. Credits

 and for the e-shop hunting spree,  for the HTML.







=====================================================================

For more information info@securax.org

Website http://www.securax.org

Advisories/Text http://www.securax.org/pers

---------------------------------------------------------------------








(C) 1999-2000 All rights reserved.