[NT] ProductCart's Database File can be Downloaded From a Remote Location

From: SecuriTeam (support_at_securiteam.com)
Date: 07/07/03

  • Next message: SecuriTeam: "[NT] VPASP SQL Injection Vulnerability"
    To: list@securiteam.com
    Date: 7 Jul 2003 18:17:54 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    Beyond Security in Canada

    Toronto-based Sunrays Technologies is now Beyond Security's representative in Canada.
    We welcome ISPs, system integrators and IT systems resellers
    to promote the most advanced vulnerability assessment solutions today.

    Contact us at 416-482-0038 or at canadasales@beyondsecurity.com

    - - - - - - - - -

      ProductCart's Database File can be Downloaded From a Remote Location
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.earlyimpact.com/productcart/> ProductCart is "an ASP shopping
    cart that combines sophisticated ecommerce features with time-saving store
    management tools and remarkable ease of use. It is widely used by many
    e-commerce sites". Due to insufficient security permissions it is possible
    for a remote user to download the product's database.

    DETAILS

    Vulnerable systems:
     * ProductCart version 1.0 up to 2.0

    In the default installation, product cart database file is located at
    /productcart/database/EIPC.mdb which can be accessed easily by any remote
    attackers.

    Sample:
    http://victimhost/productcart/database/EIPC.mdb
     
    The database file includes the store administration password as well as
    the customer's information (including credit card info).
     
    Workaround:
    Rename the database file. And put it in a protected directory.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:trihuynh@zeeup.com> Tri
    Huynh.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] VPASP SQL Injection Vulnerability"

    Relevant Pages

    • [UNIX] Cross Site Scripting Vulnerability in phpGroupWare
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Beyond Security in Canada ... Toronto-based Sunrays Technologies is now Beyond Security's representative in Canada. ... 06/25/2003 Vendor response and solutions ...
      (Securiteam)
    • [UNIX] ChangshinSoft ezTrans Server File Download Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Beyond Security in Canada ... Toronto-based Sunrays Technologies is now Beyond Security's representative in Canada. ... 2003-06-26 Second attempt to contact the vendor and system administrator. ...
      (Securiteam)
    • RE: How do you use a Security Wizard Report?
      ... Check the Security Wizard Report to see ... Once found create a shortcut to open your database file as follows: ... Microsoft Access Support ...
      (microsoft.public.access.security)
    • Re: Security in .adp?
      ... Many Access developers create an MDE database file as the front end to ... prevent users from viewing the form designs, report designs, and modules. ... security to the forms and reports, then link to the linked tables of the ADP ...
      (microsoft.public.access.security)
    • Re: Bypass message?
      ... pay the $75 luxury tax even though you passed Go. ... If you set your macro security level to low, ... able) to change the security setting or digitally sign the database file, ...
      (microsoft.public.access.tablesdbdesign)