Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1203
    posted: 07/02/08
  • NSM Daily Update #1203
    posted: 07/02/08
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1203
    posted: 07/02/08
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1201
    posted: 07/02/08
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 07/01/08

Title: iNetLab WebShop Credit Card Exposure Vulnerability

Severity: HIGH

Description:

iNetLab WebShop is an e-commerece application designed to handle the online purchases of products by customers. However, when the package is improperly configured, search engines may index the data of customers, including sensitive information such as credit card numbers.

A site using this software may put customers at risk when the package is improperly configured. By storing the information input into the software in a directory (/WebShop/ or /webshop/) that can be searched and indexed by robots and spiders, these software packages may index the data files (cc.txt) of customers and make them available on search engines. This makes it possible for a user with malicious motives to use search engines as a means of finding vulnerable sites, and then visiting the sites to gain sensitive information such as credit card numbers, addresses, and other personal information.

Affected Products:

  • iNetLab WebShop 3.4.0

References: