Title: Cart32 Admin Password Vulnerability
Severity: HIGH
Description:
Cart32 is a popular Shopping Cart systems for Windows developed by McMurtrey/Whitaker & Associates.
During a remote installation, Cart32 creates a default cart32.ini file which contains the administrator password. The password is only weakly encrypted and as such, an attacker could grab the password hash from the .ini file and crack it leading to an attacker gaining Administrator privileges. In addition, the .ini file may contain the current and past administrative passwords displayed in clear text in the Debug section of the .ini file.
Affected Products:
- McMurtrey/Whitaker & Associates Cart32 3.5.0 Build 619
References:
- McMurtrey/Whitaker & Associates: Knowledge Base Article
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.