vendor:
Comersus7F Shopping Cart Software
by:
indoushka
7,5
CVSS
HIGH
Database Disclosure
N/A
CWE
Product Name: Comersus7F Shopping Cart Software
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Asp – comersus7F Shopping Cart Software Backup Dump Vulnerability
By default, comersus.mdb isn't password-protected, and contains the following sensitive information: order information (buyer's address, phone, order status, tracking #, obs, etc), settings (encryption password, admin email, company information, etc), shipments, etc. Enough to cause damage for the business if any of that information is obtained.
Mitigation:
Password-protect the comersus.mdb file.