ProductCart's Database File can be Downloaded From a Remote Location
7 Jul. 2003
Summary
ProductCart is "an ASP shopping cart that combines sophisticated ecommerce features with time-saving store management tools and remarkable ease of use. It is widely used by many e-commerce sites". Due to insufficient security permissions it is possible for a remote user to download the product's database.
Credit:
The information has been provided by Tri Huynh.
Vulnerable systems:
* ProductCart version 1.0 up to 2.0
In the default installation, product cart database file is located at /productcart/database/EIPC.mdb which can be accessed easily by any remote attackers.