ProductCart File Disclosure Vulnerability
BID:8112
Info
ProductCart File Disclosure Vulnerability
| Bugtraq ID: | 8112 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2003 12:00AM |
| Updated: | Jul 05 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Tri Huynh" <[email protected]>. |
| Vulnerable: |
Early Impact ProductCart 2.0 br000 Early Impact ProductCart 2.0 Early Impact ProductCart 1.6003 Early Impact ProductCart 1.6002 Early Impact ProductCart 1.5004 Early Impact ProductCart 1.5003 r Early Impact ProductCart 1.5003 Early Impact ProductCart 1.5002 Early Impact ProductCart 1.6 br003 Early Impact ProductCart 1.6 br001 Early Impact ProductCart 1.6 br Early Impact ProductCart 1.6 b003 Early Impact ProductCart 1.6 b002 Early Impact ProductCart 1.6 b001 Early Impact ProductCart 1.6 b Early Impact ProductCart 1.5 |
| Not Vulnerable: | |
Exploit / POC
ProductCart File Disclosure Vulnerability
The following proof of concept was provided:
http://victimhost/productcart/database/EIPC.mdb
The following proof of concept was provided:
http://victimhost/productcart/database/EIPC.mdb
Solution / Fix
ProductCart File Disclosure Vulnerability
Solution:
The vendor has acknowledged this vulnerability and advises users to follow the guidelines provided in the "Security Recommendations for ProductCart-powered Stores" document.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has acknowledged this vulnerability and advises users to follow the guidelines provided in the "Security Recommendations for ProductCart-powered Stores" document.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ProductCart File Disclosure Vulnerability
References:
References:
- ProductCart Homepage (EarlyImpact)
- Security Recommendations for ProductCart-powered Stores (EarlyImpact)
- Re: Another ProductCart SQL Injection Vulnerability (Massimo Arrigoni
)