Cart 32 Vulnerable to Information Leakage and DoS Attack

More issues have been discovered with Card 32 software. This time it is a DoS attack and an information leakage attack.

Steve Manzuik

November 8, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported November 9, 2000 by Xato Network Security

VERSIONS AFFECTED

DESCRIPTIONTwo issues have been discovered with Cart 32 version 3.5 and below.  The first being a denial of service and the second is information leakage via specially crafted URLs.

DEMONSTRATION

The denial of service is accomplished by entering the following url; http://www.example.com/cgi-bin/c32web.exe/ShowProgress

This will cause CPU usage to jump to 100%.

The second issue, information leakage displaying full physical paths of directories can be accomplished with the following URLs; 

http://www.example.com/cgi-bin/cart32.exe/error

http://www.example.com/cgi-bin/c32web.exe/ShowAdminDir

http://www.example.com/cgi-bin/c32web.exe/CheckError?error=53

VENDOR RESPONSE

The Cart 32 team at McMurtrey/Whitaker & Associates has addressed these issues in the latest version 3.5a and has recommended that users read the knowledge base articles provided on their web site. http://www.cart32.com

CREDITDiscovered by Xato Network Security

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like