GHDB

Google Search: “Powered by A-CART”

klouw rates this entry 10 out of 10.
Submitted: 2004-10-10 00:00:00
Added by: klouw
Hits: 7661
Score: 10

A-CART is an ASP shopping cart application written in VBScript. It is comprised of a number of ASP scripts and an Access database. A security vulnerability in the product allows remote attackers to download the product’s database, thus gain access to sensitive information about users of the product (name, surname, address, e-mail, credit card number, and user’s login-password). http://www.securityfocus.com/bid/5597 (search SF for more)


Comments:

2005-03-29 10:44:21 (star):
When sql injection is given customer information can be extracted as well as the database can also be downloaded