|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[sec-adv] ProductCart Database Content Disclosure Security Issue
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Mon Jul 07 2003 - 07:54:39 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
TITLE:
ProductCart Database Content Disclosure Security Issue
READ ONLINE:
http://www.secunia.com/advisories/9195/
CRITICAL:
Highly critical
IMPACT:
Exposure of sensitive information
WHERE:
From remote
SOFTWARE:
ProductCart 1.x
ProductCart 2.x
DESCRIPTION:
A security issue has been reported in ProductCart, which may allow
malicious people to gain knowledge of sensitive information.
The problem is that ProductCart used in combination with a MS Access
database by default stores the database file in
"/productcart/database/EIPC.mdb", which can be accessed by anyone.
This may disclose the administrative password and customer
information.
SOLUTION:
Early Impact clearly warns about this issue in their manual "Security
Recommendations" available from their ProductCart Technical Support
Center. The manual also contains information about how this can be
avoided:
http://www.earlyimpact.com/pdf/ProductCart_Security_Tips.pdf
REPORTED BY / CREDITS:
Tri Huynh
----------------------------------------------------------------------
Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
Contact details:
Web : http://www.secunia.com/
E-mail : support
secunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]