iNetLab WebShop Credit Card Exposure Vulnerability
BID:2830
Info
iNetLab WebShop Credit Card Exposure Vulnerability
| Bugtraq ID: | 2830 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 22 1999 12:00AM |
| Updated: | Apr 22 1999 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Elaich Of Hhp <[email protected]> on April 22, 1999. |
| Vulnerable: |
iNetLab WebShop 3.4 |
| Not Vulnerable: | |
Discussion
iNetLab WebShop Credit Card Exposure Vulnerability
iNetLab WebShop is an e-commerece application designed to handle the online purchases of products by customers. However, when the package is improperly configured, search engines may index the data of customers, including sensitive information such as credit card numbers.
A site using this software may put customers at risk when the package is improperly configured. By storing the information input into the software in a directory that can be searched and indexed by robots and spiders, these software packages may index the data files of customers and make them available on search engines. This makes it possible for a user with malicious motives to use search engines as a means of finding vulnerable sites, and then visiting the sites to gain sensitive information such as credit card numbers, addresses, and other personal information.
iNetLab WebShop is an e-commerece application designed to handle the online purchases of products by customers. However, when the package is improperly configured, search engines may index the data of customers, including sensitive information such as credit card numbers.
A site using this software may put customers at risk when the package is improperly configured. By storing the information input into the software in a directory that can be searched and indexed by robots and spiders, these software packages may index the data files of customers and make them available on search engines. This makes it possible for a user with malicious motives to use search engines as a means of finding vulnerable sites, and then visiting the sites to gain sensitive information such as credit card numbers, addresses, and other personal information.
Exploit / POC
iNetLab WebShop Credit Card Exposure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
iNetLab WebShop Credit Card Exposure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.