[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Asp - comersus7F Shopping Cart Software Backup Dump Vulnerability

Author
indoushka
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11501
Category
web applications
Date add
29-03-2010
Platform
asp
=================================================================
Asp - comersus7F Shopping Cart Software Backup Dump Vulnerability
=================================================================

========================================================================================
| # Title    : Asp - comersus7F Shopping Cart Software Backup Dump Vulnerability
| # Author   : indoushka  
| # Home     : www.iqs3cur1ty.com
| # Bug      : Database Disclosure
======================      Exploit By indoushka       =================================
 # Exploit  :
  
 
     1- http://127.0.0.1/Comersus/database/comersus.mdb
 
# Brief Description:
 
By default, comersus.mdb isn't password-protected, and contains the following sensitive information:
    - order information (buyer's address, phone, order status, tracking #, obs, etc)
    - settings (encryption password, admin email, company information, etc)
    - shipments
    - etc
 
Enough to cause damage for the business if any of that information is obtained. 



#  0day.today [2024-11-16]  #