BugMall Shopping Cart Insecure Default Password Vulnerability
BID:24627
Info
BugMall Shopping Cart Insecure Default Password Vulnerability
| Bugtraq ID: | 24627 |
| Class: | Configuration Error |
| CVE: |
CVE-2007-3446 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | This vulnerability was discovered by t0pP8uZz and xprog. |
| Vulnerable: |
BugMall BugMall Shopping Cart 2.5 |
| Not Vulnerable: | |
Discussion
BugMall Shopping Cart Insecure Default Password Vulnerability
BugMall Shopping Cart is reported prone to an insecure-default-password vulnerability.
A remote attacker with knowledge of the default credentials that are set during installation may exploit this vulnerability to gain unauthorized access to the application.
BugMall Shopping Cart is reported prone to an insecure-default-password vulnerability.
A remote attacker with knowledge of the default credentials that are set during installation may exploit this vulnerability to gain unauthorized access to the application.
Exploit / POC
BugMall Shopping Cart Insecure Default Password Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
BugMall Shopping Cart Insecure Default Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
BugMall Shopping Cart Insecure Default Password Vulnerability
References:
References:
- Bugmall Shopping Cart Web Site (Bugmall)