OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[sec-adv] ProductCart Database Content Disclosure Security Issue

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Mon Jul 07 2003 - 07:54:39 CDT


TITLE:
ProductCart Database Content Disclosure Security Issue

READ ONLINE:
http://www.secunia.com/advisories/9195/

CRITICAL:
Highly critical

IMPACT:
Exposure of sensitive information

WHERE:
From remote

SOFTWARE:
ProductCart 1.x
ProductCart 2.x

DESCRIPTION:
A security issue has been reported in ProductCart, which may allow
malicious people to gain knowledge of sensitive information.

The problem is that ProductCart used in combination with a MS Access
database by default stores the database file in
"/productcart/database/EIPC.mdb", which can be accessed by anyone.
This may disclose the administrative password and customer
information.

SOLUTION:
Early Impact clearly warns about this issue in their manual "Security
Recommendations" available from their ProductCart Technical Support
Center. The manual also contains information about how this can be
avoided:

http://www.earlyimpact.com/pdf/ProductCart_Security_Tips.pdf

REPORTED BY / CREDITS:
Tri Huynh

----------------------------------------------------------------------

Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

Contact details:
Web : http://www.secunia.com/
E-mail : supportsecunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------