Multiple Vulnerabilities with CyberOffice Shopping Cart

Multiple vulnerabilities have been identified with CyberOffice Shopping Cart v2. A malicious attacker could either expose the personal information of other users or modify prices.

Steve Manzuik

October 1, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported October 2, 2000 by Delphis Consulting

VERSIONS AFFECTED

DESCRIPTIONMultiple vulnerabilities have been found with CyberOffice v2 running on Windows NT Server.

DEMONSTRATION

The first vulnerability makes it possible for a malicious user to modify the hidden unit price field in the HTML source then submit the form with a zero or negative values.

The second vulnerability exposes sensitive customer information including credit card data.  In its default configuration, customer order information, including credit card information is left unprotected and un-encrypted.  The information is stored in a Microsoft Access Database and is stored in a unprotected directory, /_private/

VENDOR RESPONSE

The vendor, SmartWin, has made some recommendations on fixing these problem.

The first issue, price modification, can be avoided by modifying the Authorized URL(s) setting under System Settings in the software.

To address the second issue, SmartWin recommends that users adjust the permissions to READ on the /_private/ directory.

CREDITDiscovered by Delphis Consulting

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like