|
Brought to you by:
Suppliers of:
|
|
|
| |
| DCShop is a complete shopping cart system for your e-commerce website. Multiple security vulnerabilities in the product allow attackers to gain access to sensitive files (for example, files that contain credit card numbers). |
| |
Credit:
The information has been provided by Peter Helms and David Choi.
|
| |
Multiple security vulnerabilities DCShop allow unauthorized persons via a Web browser to retrieve customer credit card numbers in clear text. Although the developers on their Web site recommend not using the beta product for commercial use, several commercial sites are using this version on production machines.
The issue shows up on improperly configured servers, i.e. where the "Everyone"-group has "Full Access" to the CGI-BIN or sub-folders.
If a request is made to the following URL:
http://www.example.com/cgi-bin/DCShop/Orders/orders.txt
The web host will send back a text file with all recent orders, including the end-users name, shipping and billing-address, e-mail address and credit card numbers with expiration dates.
It is also possible to find the administrator name and password by requesting a different file:
http://www.example.com/cgi-bin/DCShop/Auth_data/auth_user_file.txt
Solution:
To eliminate this problem, please see
http://www.dcscripts.com/dcforum/dcshop/44.html
|
|
|
|
|