BugTraq
Sensitive Information Disclosure Vulnerability in Kinetics Kiosk Product Aug 18 2005 03:21PM
Jason Coombs (jasonc science org) (1 replies)
The following script error message was noted being displayed this morning on an airline check-in kiosk manufactured by Kinetics USA.

Vendor: Kinetics USA
www.kineticsUSA.com

Line: 107
Char: 2
Error: object expected
Code: 0
URL: http://151.151.10.46:64080/attract
?time=1124376480&TransactionID=HNL_KIOSK09-050818044716

Clearly, building a product such as a publicly-accessible airline passenger check-in kiosk using Internet Explorer and Windows is a very bad design decision if you care at all about preventing this sort of information disclosure.

Even so, IE can and should be configured so as not to display such script errors.

Furthermore, the use of an IP address that is outside of the RFC 1918 private subnet address range appears very irresponsible.

Sincerely,

Jason Coombs
jasonc (at) science (dot) org [email concealed]

[ reply ]
Re: Sensitive Information Disclosure Vulnerability in Kinetics KioskProduct Aug 18 2005 06:34PM
Jay D. Dyson (jdyson treachery net)


 

Privacy Statement
Copyright 2010, SecurityFocus