Title: iNetLab WebShop Credit Card Exposure Vulnerability
Severity: HIGH
Description:
iNetLab WebShop is an e-commerece application designed to handle the online purchases of products by customers. However, when the package is improperly configured, search engines may index the data of customers, including sensitive information such as credit card numbers.
A site using this software may put customers at risk when the package is improperly configured. By storing the information input into the software in a directory (/WebShop/ or /webshop/) that can be searched and indexed by robots and spiders, these software packages may index the data files (cc.txt) of customers and make them available on search engines. This makes it possible for a user with malicious motives to use search engines as a means of finding vulnerable sites, and then visiting the sites to gain sensitive information such as credit card numbers, addresses, and other personal information.
Affected Products:
- iNetLab WebShop 3.4.0
References:
- iNetLab: WebShop Product Homepage
