Midicart PHP Information Disclosure Vulnerability
BID:5851
Info
Midicart PHP Information Disclosure Vulnerability
| Bugtraq ID: | 5851 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2002 12:00AM |
| Updated: | Oct 02 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Coxco Support Midicart PHP Plus Coxco Support Midicart PHP Maxi Coxco Support Midicart PHP |
| Not Vulnerable: | |
Discussion
Midicart PHP Information Disclosure Vulnerability
A problem with the default installation of Midicart PHP may make it possible for remote users to gain access to sensitive information.
The default installation of Midicart PHP does not place sufficient access control on files residing in the 'admin' folder. Files in this folder are meant to be accessed by privileged individuals and may contain sensitive information.
A problem with the default installation of Midicart PHP may make it possible for remote users to gain access to sensitive information.
The default installation of Midicart PHP does not place sufficient access control on files residing in the 'admin' folder. Files in this folder are meant to be accessed by privileged individuals and may contain sensitive information.
Exploit / POC
Midicart PHP Information Disclosure Vulnerability
The following proof of concept was provided:
http://<site>/admin/credit_card_info.php
The following proof of concept was provided:
http://<site>/admin/credit_card_info.php
Solution / Fix
Midicart PHP Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.