Exploit Midicart ASP - Remote Customer Information Retrieval

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21702
Проверка EDB
  1. Пройдено
Автор
DIMITRI SEKHNIASHVILI
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
cve-2002-1432
Дата публикации
2002-08-10
Код:
source: https://www.securityfocus.com/bid/5438/info

Midicart ASP is a commercially available e-commerce solution distributed by Coxco Support. It is available for the Microsoft Windows operating system.

The default installation of Midicart ASP does not place sufficient access control on the midicart.mdb file. Due to this lack of access control, it is possible for a remote user to gain access to this file. This file may yield sensitive customer information, such as customer names, addresses, and credit card information.

http://www.example.com/shoppingdirectory/midicart.mdb
 
Источник
www.exploit-db.com

Похожие темы