MidiCart Shopping Cart Software database vulnerability

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 





Summary
MIDICART is s an ASP and PHP based shopping Cart application with MS 
Access and SQL database.
A security vulnerability in the product allows remote attackers to 
download the product's
database, thus gain access to sensitive information about users of the 
product 
(name, surname, address, e-mail, phone number, credit card number, and 
company name). 
Example: 
Accessing the following URL will return the database used by the product: 
http://someshope.com/shoppingdirectory/midicart.mdb 

Additional information 
The information has been provided by Dimitri Sekhniashvili (CONTRABANDA)
E-mail: contrabanda@wanex.ge 

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux