HTTP: MidiCart Database Disclosure

This signature detects attempts to exploit a known vulnerability in MidiCart, a shopping cart application for MS Access and SQL database. MidiCart stores customer information in a database that has insecure permissions. Attackers who know where the customer database is located can use a Web browser to download it.

Extended Description

Midicart ASP is a commercially available e-commerce solution distributed by Coxco Support. It is available for the Microsoft Windows operating system. The default installation of Midicart ASP does not place sufficient access control on the midicart.mdb file. Due to this lack of access control, it is possible for a remote user to gain access to this file. This file may yield sensitive customer information, such as customer names, addresses, and credit card information.

Affected Products

Coxco_support midicart_asp_maxi

Short Name
HTTP:PHP:MIDICART-DB
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2002-1432 Database Disclosure MidiCart bid:5438
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Coxco_support

CVSS Score

5.0

Found a potential security threat?